CVE-2025-20674
02.06.2025, 03:15
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.Enginsight
Vendor | Product | Version |
---|---|---|
openwrt | openwrt | 19.07.0 |
openwrt | openwrt | 21.02.0 |
openwrt | openwrt | 21.02.0 |
openwrt | openwrt | 23.05 |
mediatek | software_development_kit | 𝑥 ≤ 7.6.7.2 |
𝑥
= Vulnerable software versions