CVE 5.5 MEDIUM

CVE-2025-20722_CVE-2025-20722

5.5 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID: MSV-3798.

Basic Information

ID CVE-2025-20722
Source MediaTek
Published Oct 14, 2025 at 09:11
Modified Oct 14, 2025 at 14:04

Affected Product

Vendor MediaTek, Inc.
Product MT6835, MT6878, MT6886, MT6897, MT6899, MT6980D, MT6985, MT6989, MT6990, MT6991, MT8676, MT8678, MT8775, MT8791T, MT8796, MT8873
Version Android 14.0, 15.0 / openWRT 21.02, 23.05 / RDKB 24Q1
Affected Versions MediaTek, Inc. MT6835, MT6878, MT6886, MT6897, MT6899, MT6980D, MT6985, MT6989, MT6990, MT6991, MT8676, MT8678, MT8775, MT8791T, MT8796, MT8873 Android 14.0, 15.0 / openWRT 21.02, 23.05 / RDKB 24Q1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.