---
id: CVE-2025-20724
title: >-
  In wlan AP driver, there is a possible out of bounds read due to an incorrect
  bounds check
summary: >-
  In wlan AP driver, there is a possible out of bounds read due to an incorrect
  bounds check. This could lead to local information disclosure with User
  execution privileges needed. User interaction is not needed for exploitation.
  Patch ID:…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-125
vendor: mediatek
product: software_development_kit
affected:
  - software_development_kit <= 7.6.7.2
  - openwrt = 19.07.0
  - openwrt = 21.02.0
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-20724'
references:
  - url: 'https://corp.mediatek.com/product-security-bulletin/October-2025'
    label: security@mediatek.com
tags:
  - nvd
epss: 0.00142
epssPercentile: 0.03033
ingestedAt: '2026-10-08T11:31:27.373Z'
---

## Overview

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418894; Issue ID: MSV-3475.

## Affected

- `software_development_kit <= 7.6.7.2`
- `openwrt = 19.07.0`
- `openwrt = 21.02.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
