CVE-2025-20633 Details
Description
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00400889; Issue ID: MSV-2491.
A high-severity out-of-bounds write vulnerability has been identified in the WLAN Access Point (AP) driver of certain MediaTek chipsets. This vulnerability arises from an incorrect bounds check, which could potentially allow for remote code execution by an adjacent attacker, without the need for additional execution privileges or user interaction. The issue affects MediaTek chipsets MT7603, MT7615, MT7622, and MT7915, specifically in the SDK release 7.4.0.1 and earlier.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://corp.mediatek.com/product-security-bulletin/February-2025 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mediatek software development kit | <= 7.4.0.1 |
CPE
Remediation
| |
| mediatek mt7603 | All versions |
CPE
Remediation
| |
| mediatek mt7615 | All versions |
CPE
Remediation
| |
| mediatek mt7622 | All versions |
CPE
Remediation
| |
| mediatek mt7915 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 18, 2025 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 3, 2025 | Initial Analysis | [email protected] |
| Feb 3, 2025 | CVE Modified | CISA-ADP |
| Feb 3, 2025 | New CVE Received | [email protected] |