{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-01T00:32:01.976","vulnerabilities":[{"cve":{"id":"CVE-2025-20674","sourceIdentifier":"security@mediatek.com","published":"2025-06-02T03:15:24.737","lastModified":"2026-06-17T08:41:48.600","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303."},{"lang":"es","value":"En el controlador del punto de acceso WLAN, existe una forma posible de inyectar un paquete arbitrario debido a la falta de verificación de permisos. Esto podría provocar una escalada remota de privilegios sin necesidad de permisos de ejecución adicionales. No se requiere la interacción del usuario para su explotación. ID de parche: WCNCR00413202; ID de problema: MSV-3303."}],"affected":[{"source":"security@mediatek.com","affectedData":[{"vendor":"MediaTek, Inc.","product":"MT6890, MT6990, MT7915, MT7916, MT7981, MT7986, MT7990, MT7992, MT7993","versions":[{"version":"SDK release 7.6.7.2 and before / OpenWrt 19.07, 21.02 (MT6890) / OpenWrt 21.02, 23.05 (MT6990)","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-03T03:55:11.100360Z","id":"CVE-2025-20674","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@mediatek.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:openwrt:openwrt:19.07.0:-:*:*:*:*:*:*","matchCriteriaId":"4FA469E2-9E63-4C9A-8EBA-10C8C870063A"},{"vulnerable":true,"criteria":"cpe:2.3:o:openwrt:openwrt:21.02.0:-:*:*:*:*:*:*","matchCriteriaId":"F0133207-2EED-4625-854F-8DB7770D5BF7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*","matchCriteriaId":"171D1C08-F055-44C0-913C-AA2B73AF5B72"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:openwrt:openwrt:21.02.0:-:*:*:*:*:*:*","matchCriteriaId":"F0133207-2EED-4625-854F-8DB7770D5BF7"},{"vulnerable":true,"criteria":"cpe:2.3:o:openwrt:openwrt:23.05:*:*:*:*:*:*:*","matchCriteriaId":"AED95D06-8EC6-4070-BE3C-E0F851D7FFC1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*","matchCriteriaId":"1A76806D-A4E3-466A-90CB-E9FFE478E7A0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:*","versionEndIncluding":"7.6.7.2","matchCriteriaId":"0DD86CC1-BD46-42D2-9112-190CCAC96B30"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*","matchCriteriaId":"171D1C08-F055-44C0-913C-AA2B73AF5B72"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*","matchCriteriaId":"1A76806D-A4E3-466A-90CB-E9FFE478E7A0"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*","matchCriteriaId":"3AB22996-9C22-4B6C-9E94-E4C055D16335"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt7916:-:*:*:*:*:*:*:*","matchCriteriaId":"DD5AA441-5381-4179-89EB-1642120F72B4"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt7981:-:*:*:*:*:*:*:*","matchCriteriaId":"490CD97B-021F-4350-AEE7-A2FA866D5889"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt7986:-:*:*:*:*:*:*:*","matchCriteriaId":"40A9E917-4B34-403F-B512-09EEBEA46811"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt7990:-:*:*:*:*:*:*:*","matchCriteriaId":"4901B2A5-B0C8-4A0C-AC17-87D469744817"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt7992:-:*:*:*:*:*:*:*","matchCriteriaId":"50D01D7D-A88D-471D-A23A-42AF4DF82952"},{"vulnerable":false,"criteria":"cpe:2.3:h:mediatek:mt7993:-:*:*:*:*:*:*:*","matchCriteriaId":"76653163-7627-4C63-A5E2-6277C0EFE23E"}]}]}],"references":[{"url":"https://corp.mediatek.com/product-security-bulletin/June-2025","source":"security@mediatek.com","tags":["Vendor Advisory"]}]}}]}