Remote Denial of Service Vulnerability in MediaTek Network Hardware
CVE-2025-20637

7.5HIGH

Key Information:

Vendor
MediaTek
Vendor
CVE Published:
3 February 2025

Summary

A potential vulnerability exists in MediaTek network hardware that could result in an unexpected system hang due to an uncaught exception. This issue allows for a remote denial of service attack to occur without any requirement for user interaction or additional execution privileges. The vulnerability is addressed in patch ID WCNCR00399035, and identified with issue ID MSV-2380.

Affected Version(s)

MT7981, MT7986 SDK release 7.6.7.0 and before

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.