Improper Input Validation in MediaTek Products
CVE-2025-20771

6.7MEDIUM

What is CVE-2025-20771?

A vulnerability in MediaTek's system software allows for the possibility of escalation of privilege due to improper input validation. An attacker with existing system privileges could exploit this weakness to gain elevated access without the need for user interaction. This flaw highlights a critical area for security improvements within device software. A patch has been issued to address the issue, underscoring the importance of regular updates to mitigate associated risks.

Affected Version(s)

MT2718, MT6739, MT6761, MT6765, MT6768, MT6781, MT6789, MT6833, MT6835, MT6853, MT6855, MT6877, MT6878, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6897, MT6899, MT6983, MT6985, MT6989, MT6991, MT8196, MT8676, MT8678, MT8792, MT8793 Android 14.0, 15.0, 16.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.