Denial of Service Vulnerability in MediaTek Wlan STA Driver
CVE-2025-20676

5.5MEDIUM

What is CVE-2025-20676?

A vulnerability in the MediaTek wlan STA driver can lead to a potential system crash due to an uncaught exception. This flaw allows for a local denial of service condition to occur, requiring user execution privileges for exploitation, but does not necessitate any user interaction. Immediate attention should be given to affected products to prevent possible disruptions.

Affected Version(s)

MT7902, MT7921, MT7922, MT7925, MT7927 NB SDK release 3.6 and before

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.