CVE-2025-20742: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00432680; Issue ID: MSV-3949.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20742?
CVE-2025-20742 is classified as a potentially critical vulnerability due to its ability to allow remote escalation of privilege.
How do I fix CVE-2025-20742?
To fix CVE-2025-20742, apply the patches provided in the relevant security bulletins from MediaTek.
Which software versions are affected by CVE-2025-20742?
CVE-2025-20742 affects MediaTek Software Development Kits up to version 7.6.7.2 and specific versions of OpenWrt including 19.07.0 and 21.02.0.
What are the consequences of exploiting CVE-2025-20742?
Exploiting CVE-2025-20742 could lead to an unauthorized remote escalation of privilege which compromises system security.
Do I need user interaction to exploit CVE-2025-20742?
No, user interaction is not required to exploit CVE-2025-20742, making it easier for attackers to leverage.