Out-of-bounds write in MediaTek products - CVE-2025-20633

 

Out-of-bounds write in MediaTek products - CVE-2025-20633

Published: February 4, 2025


Vulnerability identifier: #VU103559
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20633
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to an incorrect bounds check within wlan. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.


Affected software

MT7603
MT7615
MT7622
MT7915
VigorAP 903
Vigor2620 LTE
VigorLTE 200n
Vigor2915
Vigor2135
Vigor2765
Vigor2766
Vigor2866 LTE
Vigor2927L-5G
Vigor2927 LTE
Vigor2927
Vigor2866
Vigor2865L-5G
Vigor2865 LTE
Vigor2865
VigorAP 805
VigorAP 962C
VigorAP 1062C
Vigor C410
Vigor C510
Vigor2136

How to mitigate CVE-2025-20633

Install security update from vendor's website.

VigorAP 903 - update to 1.4.18
Vigor2620 LTE - update to 3.9.9.3
VigorLTE 200n - update to 3.9.9.3
Vigor2915 - update to 4.4.5.1
Vigor2135 - update to 4.4.5.7
Vigor2765 - update to 4.4.5.7
Vigor2766 - update to 4.4.5.7
Vigor2866 LTE - update to 4.4.6.1
Vigor2927L-5G - update to 4.4.6.1
Vigor2927 LTE - update to 4.4.6.1
Vigor2927 - update to 4.4.6.1
Vigor2866 - update to 4.4.6.1
Vigor2865L-5G - update to 4.4.6.1
Vigor2865 LTE - update to 4.4.6.1
Vigor2865 - update to 4.4.6.1
VigorAP 805 - update to 5.0.4
VigorAP 962C - update to 5.0.4
VigorAP 1062C - update to 5.0.4
Vigor C410 - update to 5.3.1
Vigor C510 - update to 5.3.1
Vigor2136 - update to 5.3.1

External References

Related Security Bulletins