CVE-2025-20738: Medium severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435342; Issue ID: MSV-4039.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20738?
CVE-2025-20738 is classified as a vulnerability that could lead to local escalation of privilege.
How do I fix CVE-2025-20738?
To fix CVE-2025-20738, apply the patch identified by Patch ID WCNCR00435342.
What systems are affected by CVE-2025-20738?
CVE-2025-20738 affects MediaTek Software Development Kit versions up to 7.6.7.2 and specific versions of OpenWrt.
Is user interaction required to exploit CVE-2025-20738?
No, user interaction is not needed to exploit CVE-2025-20738.
Can CVE-2025-20738 be exploited remotely?
CVE-2025-20738 requires that the attacker has already obtained system privileges, implying it cannot be exploited remotely.