Out of Bounds Write Vulnerability in MediaTek WLAN Access Point Driver
CVE-2025-20731

5.3MEDIUM

What is CVE-2025-20731?

The MediaTek WLAN Access Point driver contains a vulnerability that allows for an out of bounds write due to an improper bounds check. This issue could potentially enable a malicious actor to escalate privileges locally if they have previously acquired system privileges, particularly when the OceReducedNeighborReport feature is disabled. Notably, exploitation of this vulnerability does not require user interaction, making it a significant risk for affected systems. Users are advised to update to the patched version identified by Patch ID WCNCR00441511 to mitigate this risk. More information can be found in the MediaTek product security bulletin.

Affected Version(s)

MT6890, MT7615, MT7622, MT7663, MT7915, MT7916, MT7981, MT7986 SDK release 7.6.7.2 and before / openWRT 19.07, 21.02

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.