Improper Handling of Insufficient Permissions or Privileges in MediaTek products - CVE-2025-20649
Published: March 3, 2025
Vulnerability identifier: #VU105191
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20649
CWE-ID: CWE-280
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a missing permission check within Bluetooth. A local application can gain access to sensitive information.
Affected software
MT6880
MT6890
MT6980
MT6990
MT7663
MT7902
MT7925
MT7927
MT7961
MT6890
MT6980
MT6990
MT7663
MT7902
MT7925
MT7927
MT7961
How to mitigate CVE-2025-20649
Install security update from vendor's website.