CVE-2025-20654: MediaTek MT6890
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.
Affected products
- MediaTek MT6890
- MediaTek MT7622
- MediaTek MT7915
- MediaTek MT7916
- MediaTek MT7981
- MediaTek MT7986
- MediaTek Software Development Kit: up to and including 7.4.0.1; up to and including 7.6.7.0
- Openwrt Openwrt: version 19.07.0 only; version 21.02.0 only
Published 2025-04-07. Last modified 2026-06-17.