CVE-2025-20672

EUVD-2025-16598
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412257; Issue ID: MSV-3292.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
mediatekmt7902_firmware
𝑥
≤ 3.6
mediatekmt7921_firmware
𝑥
≤ 3.6
mediatekmt7922_firmware
𝑥
≤ 3.6
mediatekmt7925_firmware
𝑥
≤ 3.6
mediatekmt7927_firmware
𝑥
≤ 3.6
𝑥
= Vulnerable software versions