In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.
References
| Link | Resource |
|---|---|
| https://corp.mediatek.com/product-security-bulletin/June-2025 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
No history.
Information
Published : 2025-06-02 03:15
Updated : 2025-07-18 17:16
NVD link : CVE-2025-20674
Mitre link : CVE-2025-20674
CVE.ORG link : CVE-2025-20674
JSON object : View
Products Affected
mediatek
- mt6890
- mt7916
- mt7990
- mt7992
- mt7986
- mt7981
- mt7915
- mt7993
- software_development_kit
- mt6990
openwrt
- openwrt
CWE
CWE-863
Incorrect Authorization
