In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: MSV-4036.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediatek
Mediatek mt7902 Mediatek mt7920 Mediatek mt7921 Mediatek mt7922 Mediatek mt7925 Mediatek mt7927 Mediatek software Development Kit |
|
| CPEs | cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7920:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7922:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mediatek
Mediatek mt7902 Mediatek mt7920 Mediatek mt7921 Mediatek mt7922 Mediatek mt7925 Mediatek mt7927 Mediatek software Development Kit |
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediatk
Mediatk mt7902 Mediatk mt7920 Mediatk mt7921 Mediatk mt7922 Mediatk mt7925 Mediatk mt7927 |
|
| Vendors & Products |
Mediatk
Mediatk mt7902 Mediatk mt7920 Mediatk mt7921 Mediatk mt7922 Mediatk mt7925 Mediatk mt7927 |
Tue, 04 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 04 Nov 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In wlan STA driver, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435337; Issue ID: MSV-4036. | |
| Weaknesses | CWE-367 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published: 2025-11-04T06:19:54.584Z
Updated: 2025-11-04T15:04:25.506Z
Reserved: 2024-11-01T01:21:50.395Z
Link: CVE-2025-20740
Updated: 2025-11-04T15:04:18.842Z
Status : Analyzed
Published: 2025-11-04T07:15:44.140
Modified: 2025-11-05T17:12:30.767
Link: CVE-2025-20740
No data.