In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.
                
            References
                    | Link | Resource | 
|---|---|
| https://corp.mediatek.com/product-security-bulletin/June-2025 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
History
                    18 Jul 2025, 17:16
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Mediatek software Development Kit | |
| CPE | cpe:2.3:o:mediatek:mt7915_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7992_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7986_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7990_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7916_firmware:7.6.7.2:*:*:*:*:*:*:* cpe:2.3:o:mediatek:mt7981_firmware:7.6.7.2:*:*:*:*:*:*:* | cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:* | 
02 Jul 2025, 15:39
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-02 03:15
Updated : 2025-07-18 17:16
NVD link : CVE-2025-20674
Mitre link : CVE-2025-20674
CVE.ORG link : CVE-2025-20674
JSON object : View
Products Affected
                mediatek
- mt7992
- mt7915
- mt7993
- mt6890
- mt6990
- mt7986
- mt7916
- mt7990
- mt7981
- software_development_kit
openwrt
- openwrt
CWE
                
                    
                        
                        CWE-863
                        
            Incorrect Authorization
