CVE-2025-20654 - CVE House
Back to Database
Status published Unknown CVE-2025-20654

In wlan service, there is a possible out of bounds...

Vulnerability Description

In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-20654

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

MediaTek, Inc.

View all reports →

Affected Software

MT6890, MT7622, MT7915, MT7916, MT7981, MT7986
Vulnerable Versions:
SDK version 7.4.0.1 and before (for MT7622 and MT7915) / SDK version 7.6.7.0 and before (for MT7916, MT7981 and MT7986) / OpenWrt 19.07, 21.02 (for MT6890)

Timeline

Official Publish: April 7th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)