Out of Bounds Read Vulnerability in MediaTek WLAN Driver
CVE-2025-20740
Key Information:
- Vendor
MediaTek
- Vendor
- CVE Published:
- 4 November 2025
What is CVE-2025-20740?
A vulnerability exists in the WLAN STA driver that allows for a potential out of bounds read due to a race condition. This situation can lead to a local information disclosure risk, requiring user execution privileges for exploitation. Notably, user interaction is not necessary to exploit this vulnerability. To address this issue, a patch has been issued under ID WCNCR00435337, associated with Issue ID MSV-4036. For more comprehensive details, refer to the MediaTek product security bulletin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MT7902, MT7920, MT7921, MT7922, MT7925, MT7927 NB SDK release 3.7 and before
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
