CVE-2025-20741: Medium severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422; Issue ID: MSV-3958.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20741?
CVE-2025-20741 is classified as a vulnerability with the potential for local escalation of privilege.
How do I fix CVE-2025-20741?
To fix CVE-2025-20741, apply the patch identified by Patch ID WCNCR00434422.
Which software versions are affected by CVE-2025-20741?
CVE-2025-20741 affects MediaTek Software Development Kit versions up to and including 7.6.7.2 and OpenWrt versions 19.07.0 and 21.02.0.
Who could exploit CVE-2025-20741?
CVE-2025-20741 could be exploited by a malicious actor who has already obtained System privilege.
Is user interaction required to exploit CVE-2025-20741?
No, user interaction is not required to exploit CVE-2025-20741.