← All CVEs

CVE-2025-20680

critical · 9.8

In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418044; Issue ID: MSV-3482.

9.8
CVSS
0.7%
EPSS (exploit prob.)
51st
EPSS percentile
2025-07-08
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122

Affected products

VendorProductAffected versions
mediateknbiot_sdk<= 3.6
mediatekmt7902all versions
mediatekmt7920all versions
mediatekmt7921all versions
mediatekmt7922all versions
mediatekmt7925all versions
mediatekmt7927all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-20680