CVE-2025-20713

7.8

MediaTek · WLAN AP Driver

A stack-based buffer overflow exists in the MediaTek WLAN AP driver due to an improper bounds check, potentially allowing local privilege escalation.

Executive summary

A vulnerability in the MediaTek WLAN AP driver could allow an attacker with system-level access to achieve further privilege escalation via a stack overflow.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) occurring within the WLAN AP driver, triggered by an incorrect bounds check. While the vector requires local access, an authenticated user with system privileges could exploit this to escalate their control over the affected device.

Business impact

Successful exploitation of this flaw allows an attacker to escalate privileges, which could result in a full compromise of the affected network device. Given the CVSS score of 7.8, the risk is significant for embedded infrastructure and wireless access points, potentially leading to unauthorized network control or persistent access for an adversary.

Remediation

Immediate Action: Apply the vendor-provided security updates or patch ID WCNCR00432661 identified in the MediaTek product security bulletin.

Proactive Monitoring: Monitor system logs for unusual kernel-level crashes or unexpected process behavior associated with the wireless driver stack.

Compensating Controls: Ensure that access to the underlying system is strictly limited to authorized personnel to prevent the initial access required for this local privilege escalation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing MediaTek hardware should verify their current SDK or firmware versions against the affected list immediately. Prioritize patching devices that serve as critical network infrastructure or gatekeepers to internal segments, as this vulnerability represents a significant risk to the integrity of the wireless management environment.

More MediaTek CVEs

Sources