In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00447115; Issue ID: MSV-4276.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediatek software Development Kit
|
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:mediatek:software_development_kit:3.7:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7920:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7922:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mediatek software Development Kit
|
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediatek
Mediatek mt7902 Mediatek mt7920 Mediatek mt7921 Mediatek mt7922 Mediatek mt7925 Mediatek mt7927 |
|
| Vendors & Products |
Mediatek
Mediatek mt7902 Mediatek mt7920 Mediatek mt7921 Mediatek mt7922 Mediatek mt7925 Mediatek mt7927 |
Tue, 04 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 04 Nov 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00447115; Issue ID: MSV-4276. | |
| Weaknesses | CWE-122 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published: 2025-11-04T06:19:45.290Z
Updated: 2025-11-05T04:55:39.588Z
Reserved: 2024-11-01T01:21:50.393Z
Link: CVE-2025-20728
Updated: 2025-11-04T15:08:31.543Z
Status : Analyzed
Published: 2025-11-04T07:15:35.100
Modified: 2025-11-05T17:14:09.840
Link: CVE-2025-20728
No data.