Out of Bounds Write Vulnerability in MediaTek WLAN AP Driver
CVE-2025-20739

6.7MEDIUM

What is CVE-2025-20739?

A vulnerability exists in the MediaTek WLAN Access Point driver due to an improper bounds check within the code. This issue can allow a malicious actor to perform an out of bounds write, which can potentially lead to a local escalation of privilege, assuming the attacker has already gained system-level access. Importantly, no user interaction is required for this vulnerability to be exploited. This situation underscores the need for immediate attention and patching to ensure device security from potential threats.

Affected Version(s)

MT6890, MT7615, MT7622, MT7663, MT7915, MT7916, MT7981, MT7986 SDK release 7.6.7.2 and before / openWRT 19.07, 21.02

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.