CVE-2025-20684

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416939; Issue ID: MSV-3422.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*

History

09 Jul 2025, 17:24

Type Values Removed Values Added
CPE cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*
cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*
References () https://corp.mediatek.com/product-security-bulletin/July-2025 - () https://corp.mediatek.com/product-security-bulletin/July-2025 - Vendor Advisory
First Time Mediatek software Development Kit
Mediatek mt7622
Mediatek mt7615
Mediatek mt7663
Mediatek

08 Jul 2025, 14:15

Type Values Removed Values Added
CWE CWE-787

08 Jul 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 03:15

Updated : 2025-07-09 17:24


NVD link : CVE-2025-20684

Mitre link : CVE-2025-20684


JSON object : View

Products Affected

mediatek

  • mt7663
  • mt7622
  • mt7615
  • software_development_kit
CWE

No CWE.