In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09812521; Issue ID: MSV-3421.
References
Link | Resource |
---|---|
https://corp.mediatek.com/product-security-bulletin/July-2025 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
09 Jul 2025, 17:22
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mediatek mt6985
Mediatek mt7922 Mediatek mt6899 Openwrt Mediatek mt7923 Mediatek mt6991 Mediatek mt7902 Mediatek mt8893 Mediatek mt7920 Linuxfoundation yocto Mediatek mt7927 Mediatek software Development Kit Mediatek mt6897 Mediatek mt6989 Openwrt openwrt Google android Mediatek mt6990 Mediatek mt7921 Mediatek Mediatek mt2737 Mediatek mt8678 Mediatek mt8796 Mediatek mt7932 Mediatek mt6886 Mediatek mt6835 Mediatek mt8196 Mediatek mt7925 Mediatek mt6878 Linuxfoundation |
|
References | () https://corp.mediatek.com/product-security-bulletin/July-2025 - Vendor Advisory | |
CPE | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:* cpe:2.3:o:openwrt:openwrt:23.05:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7922:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8796:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7923:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:* cpe:2.3:o:openwrt:openwrt:21.02.0:-:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:* cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7932:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt2737:-:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7920:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt8196:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:* cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:* |
08 Jul 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
08 Jul 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-08 03:15
Updated : 2025-07-09 17:22
NVD link : CVE-2025-20693
Mitre link : CVE-2025-20693
CVE.ORG link : CVE-2025-20693
JSON object : View
Products Affected
mediatek
- mt6897
- mt6990
- mt6886
- mt7921
- mt6878
- mt7932
- mt6991
- mt6989
- mt7902
- mt6835
- mt7927
- mt7922
- mt7920
- mt6899
- mt2737
- mt6985
- mt8796
- mt8678
- mt8196
- mt8893
- software_development_kit
- mt7925
- mt7923
- android
openwrt
- openwrt
linuxfoundation
- yocto
CWE
CWE-125
Out-of-bounds Read