CVE-2025-20739: Medium severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435340; Issue ID: MSV-4038.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20739?
CVE-2025-20739 has a high severity due to the potential for local escalation of privilege.
How do I fix CVE-2025-20739?
To fix CVE-2025-20739, apply the available patches specifically provided in the patch ID WCNCR00435340.
Who is affected by CVE-2025-20739?
Devices running vulnerable versions of the MediaTek Software Development Kit and specific versions of OpenWrt are affected by CVE-2025-20739.
Can CVE-2025-20739 be exploited remotely?
No, CVE-2025-20739 requires that the malicious actor has already obtained System privileges for exploitation.
What potential impact does CVE-2025-20739 have?
CVE-2025-20739 can enable a local escalation of privilege for users who have System privileges, potentially compromising the device's security.