← All CVEs

CVE-2025-20674

critical · 9.8

In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.

9.8
CVSS
0.8%
EPSS (exploit prob.)
54th
EPSS percentile
2025-06-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-863

Affected products

VendorProductAffected versions
openwrtopenwrt19.07.0
openwrtopenwrt21.02.0
mediatekmt6890all versions
openwrtopenwrt21.02.0
openwrtopenwrt23.05
mediatekmt6990all versions
mediateksoftware_development_kit<= 7.6.7.2
mediatekmt6890all versions
mediatekmt6990all versions
mediatekmt7915all versions
mediatekmt7916all versions
mediatekmt7981all versions
mediatekmt7986all versions
mediatekmt7990all versions
mediatekmt7992all versions
mediatekmt7993all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-20674