CVE-2025-20674
02.06.2025, 03:15
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openwrt | openwrt | 19.07.0 |
| openwrt | openwrt | 21.02.0 |
| openwrt | openwrt | 21.02.0 |
| openwrt | openwrt | 23.05 |
| mediatek | software_development_kit | 𝑥 ≤ 7.6.7.2 |
𝑥
= Vulnerable software versions