April 2025 Product Security Bulletin

Published 2025-04-07
The MediaTek Product Security Bulletin contains details of security vulnerabilities affecting MediaTek Smartphone, Tablet, AIoT, Smart display, Smart platform, OTT, Computer Vision, Audio, and TV chipsets. Device OEMs have been notified of all the issues and the corresponding security patches for at least two months before publication.

The severity of the identified vulnerabilities was conducted based on the Common Vulnerability Scoring System version 3.1 (CVSS v3.1).


Summary

Severity CVEs
Critical CVE-2025-20654
High CVE-2025-20655, CVE-2025-20656, CVE-2025-20657, CVE-2025-20658
Medium CVE-2025-20659, CVE-2025-20660, CVE-2025-20661, CVE-2025-20662, CVE-2025-20663, CVE-2025-20664


Details

CVE CVE-2025-20654
Title Out-of-bounds write in wlan
Severity Critical
Vulnerability Type RCE
CWE CWE-787 Out-of-bounds Write
Description In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Chipsets MT6890, MT7622, MT7915, MT7916, MT7981, MT7986
Affected Software Versions SDK version 7.4.0.1 and before (for MT7622 and MT7915) / SDK version 7.6.7.0 and before (for MT7916, MT7981 and MT7986) / OpenWrt 19.07, 21.02 (for MT6890)
Report Source External

CVE CVE-2025-20655
Title Out-of-bounds read in keymaster
Severity High
Vulnerability Type ID
CWE CWE-125 Out-of-bounds Read
Description In keymaster, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation.
Affected Chipsets MT9972
Affected Software Versions Android 12.0, 14.0
Report Source External

CVE CVE-2025-20656
Title Out-of-bounds write in DA
Severity High
Vulnerability Type EoP
CWE CWE-787 Out-of-bounds Write
Description In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Chipsets MT6781, MT6789, MT6835, MT6855, MT6878, MT6879, MT6886, MT6895, MT6897, MT6983, MT6985, MT6989, MT6990, MT8196, MT8370, MT8390
Affected Software Versions Android 12.0, 13.0, 14.0, 15.0 / openWRT 21.02, 23.05 / Yocto 4.0 / RDK-B 24Q1
Report Source Internal

CVE CVE-2025-20657
Title Out-of-bounds write in vdec
Severity High
Vulnerability Type EoP
CWE CWE-787 Out-of-bounds Write
Description In vdec, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation.
Affected Chipsets MT6765, MT6768, MT6781, MT6789, MT6833, MT6853, MT6877, MT6885, MT8768, MT8771, MT8781, MT8786, MT8791T
Affected Software Versions Android 12.0, 15.0
Report Source Internal

CVE CVE-2025-20658
Title Out-of-bounds write in DA
Severity High
Vulnerability Type EoP
CWE CWE-787 Out-of-bounds Write
Description In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Chipsets MT2718, MT6781, MT6789, MT6835, MT6855, MT6878, MT6879, MT6886, MT6895, MT6897, MT6983, MT6985, MT6989, MT8196, MT8673, MT8676, MT8678, MT8781
Affected Software Versions Android 12.0, 13.0, 14.0, 15.0
Report Source Internal

CVE CVE-2025-20659
Title Out-of-bounds read in Modem
Severity Medium
Vulnerability Type DoS
CWE CWE-125 Out-of-bounds Read
Description In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Chipsets MT2735, MT2737, MT6739, MT6761, MT6762, MT6762D, MT6762M, MT6763, MT6765, MT6765T, MT6767, MT6768, MT6769, MT6769K, MT6769S, MT6769T, MT6769Z, MT6771, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6813, MT6833, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6878, MT6878M, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6899, MT6980, MT6980D, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT6991, MT8666, MT8667, MT8673, MT8675, MT8676, MT8678, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8791T, MT8796, MT8797, MT8798, MT8863
Affected Software Versions Modem LR12A, LR13, NR15, NR16, NR17, NR17R
Report Source External

CVE CVE-2025-20660
Title Out-of-bounds read in drmserver
Severity Medium
Vulnerability Type ID
CWE CWE-125 Out-of-bounds Read
Description In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation.
Affected Chipsets MT9972
Affected Software Versions Android 12.0, 14.0
Report Source External

CVE CVE-2025-20661
Title Out-of-bounds read in drmserver
Severity Medium
Vulnerability Type ID
CWE CWE-125 Out-of-bounds Read
Description In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation.
Affected Chipsets MT9972
Affected Software Versions Android 12.0, 14.0
Report Source External

CVE CVE-2025-20662
Title Out-of-bounds read in drmserver
Severity Medium
Vulnerability Type ID
CWE CWE-125 Out-of-bounds Read
Description In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation.
Affected Chipsets MT9972
Affected Software Versions Android 12.0, 14.0
Report Source External

CVE CVE-2025-20663
Title Uncaught exception in wlan
Severity Medium
Vulnerability Type ID
CWE CWE-248 Uncaught Exception
Description In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Chipsets MT7915, MT7916, MT7981, MT7986
Affected Software Versions SDK release 7.4.0.1 (MT7915) and 7.6.7.2 (MT7916, MT798X) and before
Report Source External

CVE CVE-2025-20664
Title Uncaught exception in wlan
Severity Medium
Vulnerability Type ID
CWE CWE-248 Uncaught Exception
Description In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Chipsets MT7915, MT7916, MT7981, MT7986, MT7990, MT7992
Affected Software Versions SDK release 7.4.0.1 (MT7915) and 7.6.7.2 (MT7916, MT798X) and 8.2.1.4 (MT799X) and before
Report Source External


Vulnerability Type Definition

Abbreviation Definition
RCE Remote Code Execution
EoP Elevation of Privilege
ID Information Disclosure
DoS Denial of Service
N/A Classification not available


Versions

Version Date Description
1.0 April 7, 2025 Bulletin published.


Notes

Information above is generated only at the time of creation of this Security Bulletin. The list of affected chipsets could be not complete. For any further information, device OEMs can reach your MediaTek contact person if needed.

If you want to report a security vulnerability in MediaTek chipsets or products, please go to Report Security Vulnerability page on MediaTek website.