Memory Corruption Vulnerability in MediaTek Products
CVE-2025-20705

7.8HIGH

What is CVE-2025-20705?

A memory corruption issue has been identified within the monitor_hang function in MediaTek products, resulting from a use-after-free flaw. This vulnerability could allow an attacker with local system privileges to escalate their privileges without requiring user interaction. To mitigate this risk, it is highly recommended to apply the latest patches and updates provided by MediaTek.

Affected Version(s)

MT2718, MT2735, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6893, MT6895, MT6897, MT6899, MT6980D, MT6983, MT6985, MT6989, MT6990, MT6991, MT8169, MT8186, MT8188, MT8676, MT8678, MT8696, MT8775, MT8792, MT8796 Android 13.0, 14.0, 15.0, 16.0 / openWRT 19.07, 21.02 / Yocto 2.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20705 : Memory Corruption Vulnerability in MediaTek Products