Out-of-bounds write in MediaTek products - CVE-2025-20716

 

Out-of-bounds write in MediaTek products - CVE-2025-20716

Published: October 8, 2025


Vulnerability identifier: #VU116743
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20716
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to perform service disruption.

The vulnerability exists due to an incorrect bounds check within wlan. A local application can perform service disruption.


Affected software

MT6890
MT7615
MT7622
MT7663
MT7915
MT7916
MT7981
MT7986
Lenovo Idea Tab Pro (TB373FU)
TB373FU Lenovo Idea Tab Pro
VigorAP 903
Vigor 2912n
Vigor 2133n
Vigor 2762n
Vigor 2620Ln
Vigor 2915ac
Vigor 2927Lac
Vigor 2927Vac
Vigor 2927ac
Vigor 2766Vac
Vigor 2866Lac
Vigor 2866Vac
Vigor 2866ac
Vigor 2865Lac
Vigor 2865Vac
Vigor 2865ac
Vigor 2766ac
Vigor 2765Vac
Vigor 2765ac
Vigor 2763ac
Vigor 2135FVac
Vigor 2135Vac
Vigor 2135ac
Vigor C410ax
Vigor 2136ax
Vigor C510ax

How to mitigate CVE-2025-20716

Install security update from vendor's website.

VigorAP 903 - update to 1.4.20
Vigor 2912n - update to 3.8.18
Vigor 2133n - update to 3.9.9.5
Vigor 2762n - update to 3.9.9.5
Vigor 2620Ln - update to 3.9.9.6
Vigor 2915ac - update to 4.4.6.2
Vigor 2927Lac - update to 4.5.1.1
Vigor 2927Vac - update to 4.5.1.1
Vigor 2927ac - update to 4.5.1.1
Vigor 2766Vac - update to 4.5.2
Vigor 2866Lac - update to 4.5.2
Vigor 2866Vac - update to 4.5.2
Vigor 2866ac - update to 4.5.2
Vigor 2865Lac - update to 4.5.2
Vigor 2865Vac - update to 4.5.2
Vigor 2865ac - update to 4.5.2
Vigor 2766ac - update to 4.5.2
Vigor 2765Vac - update to 4.5.2
Vigor 2765ac - update to 4.5.2
Vigor 2763ac - update to 4.5.2
Vigor 2135FVac - update to 4.5.2
Vigor 2135Vac - update to 4.5.2
Vigor 2135ac - update to 4.5.2
Vigor C410ax - update to 5.3.5
Vigor 2136ax - update to 5.3.5
Vigor C510ax - update to 5.3.5

External References

Related Security Bulletins