{"id":"CVE-2025-20709","title":"In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check","summary":"In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not ne…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-120"],"vendor":"mediatek","product":"software_development_kit","affected":["software_development_kit <= 7.6.7.2","openwrt = 19.07.0","openwrt = 21.02.0"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-20709","references":[{"url":"https://corp.mediatek.com/product-security-bulletin/October-2025","label":"security@mediatek.com"}],"tags":["nvd"],"epss":0.00307,"epssPercentile":0.21513,"ingestedAt":"2026-10-08T11:31:27.368Z","slug":"CVE-2025-20709","body":"## Overview\n\nIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00415809; Issue ID: MSV-3405.\n\n## Affected\n\n- `software_development_kit <= 7.6.7.2`\n- `openwrt = 19.07.0`\n- `openwrt = 21.02.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}