Information Disclosure Vulnerability in Mediatek Wireless Access Point Driver
CVE-2025-20663

7.5HIGH

Key Information:

Vendor
MediaTek
Vendor
CVE Published:
7 April 2025

Summary

A potential information disclosure vulnerability exists within the Mediatek Wireless Access Point Driver. This issue arises from an uncaught exception during operation, which allows for the possibility of exposing sensitive information to remote adversaries situated in close proximity to the vulnerable device. The vulnerability does not require any additional execution privileges or user interaction, increasing the risk of exploitation and the potential for unauthorized data access.

Affected Version(s)

MT7915, MT7916, MT7981, MT7986 SDK release 7.4.0.1 (MT7915) and 7.6.7.2 (MT7916, MT798X) and before

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.