← All CVEs

CVE-2025-20672

critical · 9.8

In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412257; Issue ID: MSV-3292.

9.8
CVSS
0.6%
EPSS (exploit prob.)
49th
EPSS percentile
2025-06-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122

Affected products

VendorProductAffected versions
mediatekmt7902_firmware<= 3.6
mediatekmt7902all versions
mediatekmt7921_firmware<= 3.6
mediatekmt7921all versions
mediatekmt7922_firmware<= 3.6
mediatekmt7922all versions
mediatekmt7925_firmware<= 3.6
mediatekmt7925all versions
mediatekmt7927_firmware<= 3.6
mediatekmt7927all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-20672