CERT-In Vulnerability Note
CIVN-2025-0119
Multiple Vulnerabilities in MediaTek Products
Original Issue Date:June 11, 2025
Severity Rating: HIGH
Software Affected
- MediaTek NB SDK versions prior to 3.6 for MT7902, MT7921, MT7922, MT7925, MT7927
- MediaTek SDK versions prior to 7.6.7.2/ OpenWrt 19.07, 21.02 (MT6890) / OpenWrt 21.02, 23.05 (MT6990) for MT6890, MT6990, MT7915, MT7916, MT7981, MT7986, MT7990, MT7992, MT7993
- MediaTek Modem LR12A, LR13, NR15, NR16, NR17, NR17R for MT6739, MT6761, MT6762, MT6762D, MT6762M, MT6763, MT6765, MT6765T, MT6767, MT6768, MT6769, MT6769K, MT6769S, MT6769T, MT6769Z, MT6771, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6813, MT6833, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6878, MT6878M, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6899, MT6980, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT6991, MT8666, MT8667, MT8673, MT8675, MT8676, MT8678, MT8765, MT8766, MT8766R, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8789, MT8791, MT8791T, MT8795T, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893
Overview
Multiple vulnerabilities have been reported in MediaTek products which could allow an attacker to gain elevated privileges or cause denial of service condition on the targeted system.
Target Audience: All organization and individuals using MediaTek products.
Risk Assessment: Potential for data theft and system instability.
Impact Assessment: Critical risk on confidentiality, integrity, and availability of systems.
Description
Multiple vulnerabilities exist in the MediaTek products due to heap overflow & null pointer dereference in bluetooth, null pointer dereference & incorrect authorization in wlan and uncontrolled recursion in ims service.
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges or cause denial of service condition on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://corp.mediatek.com/product-security-bulletin/June-2025
Vendor Information
MediaTek
https://corp.mediatek.com/product-security-bulletin/June-2025
References
MediaTek
https://corp.mediatek.com/product-security-bulletin/June-2025
CVE Name
CVE-2025-20672
CVE-2025-20673
CVE-2025-20674
CVE-2025-20675
CVE-2025-20676
CVE-2025-20677
CVE-2025-20678
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|