In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/June-2025 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
18 Jul 2025, 17:16
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mediatek software Development Kit
|
|
CPE | cpe:2.3:o:mediatek:mt7915_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7992_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7986_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7990_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7916_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7981_firmware:7.6.7.2:*:*:*:*:*:*:* |
cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:* |
02 Jul 2025, 15:39
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-02 03:15
Updated : 2025-07-18 17:16
NVD link : CVE-2025-20674
Mitre link : CVE-2025-20674
CVE.ORG link : CVE-2025-20674
JSON object : View
Products Affected
mediatek
- mt7992
- mt7915
- mt7993
- mt6890
- mt6990
- mt7986
- mt7916
- mt7990
- mt7981
- software_development_kit
openwrt
- openwrt
CWE
CWE-863
Incorrect Authorization