CVE-2025-20649

In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:o:openwrt:openwrt:23.05:*:*:*:*:*:*:*
OR cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7961:-:*:*:*:*:*:*:*

History

22 Apr 2025, 13:46

Type Values Removed Values Added
First Time Mediatek mt6880
Mediatek mt7927
Mediatek mt7961
Mediatek mt7902
Mediatek mt7925
Openwrt openwrt
Mediatek software Development Kit
Mediatek mt7663
Mediatek mt6980
Mediatek mt6990
Openwrt
Mediatek mt6890
Mediatek
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:mediatek:software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7663:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7961:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
cpe:2.3:o:openwrt:openwrt:23.05:*:*:*:*:*:*:*
References () https://corp.mediatek.com/product-security-bulletin/March-2025 - () https://corp.mediatek.com/product-security-bulletin/March-2025 - Vendor Advisory

04 Mar 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) En Bluetooth Stack SW, existe una posible divulgación de información debido a la falta de una verificación de permisos. Esto podría provocar la divulgación de información remota (proximal/adyacente) sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación. ID de parche: WCNCR00396437; ID de problema: MSV-2184.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

03 Mar 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 03:15

Updated : 2025-04-22 13:46


NVD link : CVE-2025-20649

Mitre link : CVE-2025-20649

CVE.ORG link : CVE-2025-20649


JSON object : View

Products Affected

mediatek

  • mt7961
  • mt6890
  • mt6980
  • mt7925
  • mt7927
  • software_development_kit
  • mt7902
  • mt6990
  • mt6880
  • mt7663

openwrt

  • openwrt
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges

NVD-CWE-noinfo