PT-2025-15168 · Da · Da

Published

2025-04-07

·

Updated

2026-02-01

·

CVE-2025-20656

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DA (affected versions not specified)
Description The component DA within MediaTek firmware has a potential out-of-bounds write issue due to a missing bounds check. Successful exploitation of this issue could allow an attacker to gain local privilege escalation and potentially disclose protected information. An attacker requires physical access to the device, and no additional execution privileges or user interaction are needed for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Memory Corruption

Weakness Enumeration

Related Identifiers

ASB-A-393950961
BDU:2025-14892
CVE-2025-20656
M-ALPS09625423

Affected Products

Da