In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441510; Issue ID: MSV-4139.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediatk
Mediatk mt6890 Mediatk mt7615 Mediatk mt7622 Mediatk mt7663 Mediatk mt7915 Mediatk mt7916 Mediatk mt7981 Mediatk mt7986 |
|
| Vendors & Products |
Mediatk
Mediatk mt6890 Mediatk mt7615 Mediatk mt7622 Mediatk mt7663 Mediatk mt7915 Mediatk mt7916 Mediatk mt7981 Mediatk mt7986 |
Tue, 04 Nov 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441510; Issue ID: MSV-4139. | |
| Weaknesses | CWE-121 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published: 2025-11-04T06:20:08.954Z
Updated: 2025-11-04T20:42:51.075Z
Reserved: 2024-11-01T01:21:50.394Z
Link: CVE-2025-20732
No data.
Status : Undergoing Analysis
Published: 2025-11-04T07:15:37.820
Modified: 2025-11-04T21:15:35.713
Link: CVE-2025-20732
No data.