CVE-2025-20741PoC(mediatek / mt6890)

LOWCVSS 6.7 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00434422; Issue ID: MSV-3958.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mt6890
  • mt7615
  • mt7622
  • mt7663

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
mt6890mt7615mt7622mt7663mt7915mt7916mt7981mt7986openwrtsoftware_development_kit

3 versions affected across 10 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-03: 1Technical Details · 2026-04-03: 104-03
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • hypr@hyprdude
    PoC

    New post is up! This one uses CVE-2025-20741 (a heap overflow in the MediaTek MT76xx driver) to show how a bit of kernel alchemy can turn a heap OOB write into a number of stronger exploit primitives, up to page-level r/w via pipe_buffer corruption :) https://blog.coffinsec.com/0day/2026/04/02/kernel-alchemy-pt1.html

    Post summary

    The blog post demonstrates a PoC for CVE‑2025‑20741, explaining how an initial heap overflow can be leveraged into stronger kernel primitives, but does not mention active exploitation or a patch.

    4100138025527.5K
    3.0K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
HWmediatekmt6890---
HWmediatekmt7615---
HWmediatekmt7622---
HWmediatekmt7663---
HWmediatekmt7915---
HWmediatekmt7916---
HWmediatekmt7981---
HWmediatekmt7986---
Appmediateksoftware_development_kit---
OSopenwrtopenwrt19.07.0--
OSopenwrtopenwrt21.02.0--

Explore more