CVE-2025-20737: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435343; Issue ID: MSV-4040.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20737?
CVE-2025-20737 is considered a medium severity vulnerability due to potential local escalation of privilege.
How do I fix CVE-2025-20737?
To fix CVE-2025-20737, apply the patch ID WCNCR00435343 provided by the vendor.
What systems are affected by CVE-2025-20737?
CVE-2025-20737 affects specific versions of the MediaTek Software Development Kit and OpenWrt version 19.07.0 and 21.02.0.
What type of vulnerability is CVE-2025-20737?
CVE-2025-20737 is an out of bounds write vulnerability due to incorrect bounds checking in the wlan AP driver.
Do I need user interaction to exploit CVE-2025-20737?
No, user interaction is not needed for the exploitation of CVE-2025-20737.