CVE-2025-20649

In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:o:openwrt:openwrt:23.05:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7961:-:*:*:*:*:*:*:*

History

22 Apr 2025, 13:46

Type Values Removed Values Added
CPE cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7961:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
cpe:2.3:o:openwrt:openwrt:23.05:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Mediatek
Mediatek software Development Kit
Mediatek mt7927
Mediatek mt6980
Mediatek mt6890
Mediatek mt7925
Mediatek mt7902
Openwrt openwrt
Mediatek mt6990
Mediatek mt7663
Mediatek mt6880
Mediatek mt7961
Openwrt
References () https://corp.mediatek.com/product-security-bulletin/March-2025 - () https://corp.mediatek.com/product-security-bulletin/March-2025 - Vendor Advisory

04 Mar 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) En Bluetooth Stack SW, existe una posible divulgación de información debido a la falta de una verificación de permisos. Esto podría provocar la divulgación de información remota (proximal/adyacente) sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación. ID de parche: WCNCR00396437; ID de problema: MSV-2184.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

03 Mar 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 03:15

Updated : 2025-04-22 13:46


NVD link : CVE-2025-20649

Mitre link : CVE-2025-20649

CVE.ORG link : CVE-2025-20649


JSON object : View

Products Affected

mediatek

  • mt6890
  • mt6990
  • mt7663
  • mt6880
  • mt7961
  • mt7925
  • mt6980
  • software_development_kit
  • mt7927
  • mt7902

openwrt

  • openwrt
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges

NVD-CWE-noinfo