Out-of-bounds read in MediaTek products - CVE-2025-20648
Published: March 3, 2025
Vulnerability identifier: #VU105190
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20648
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing bounds check within apu. A local application can gain access to sensitive information.
Affected software
MT2718
MT6879
MT6989
MT8196
MT8370
MT8390
MT8395
MT8673
MT8678
MT6879
MT6989
MT8196
MT8370
MT8390
MT8395
MT8673
MT8678
How to mitigate CVE-2025-20648
Install security update from vendor's website.