Medium severity6.7NVD Advisory· Published Nov 4, 2025· Updated Jun 17, 2026
CVE-2025-20746
CVE-2025-20746
Description
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- MediaTek, Inc./MT2718, MT2737, MT6835, MT6878, MT6886, MT6897, MT6899, MT6982, MT6985, MT6986, MT6986D, MT6989, MT6990, MT6991, MT8676, MT8678, MT8755, MT8893v5Range: Android 14.0, 15.0 / openWRT 21.02, 23.05 / Yocto 4.0 / RDK-B 24Q1 / Zephyr 3.7.0
- cpe:2.3:a:linuxfoundation:yocto:4.0:*:*:*:*:*:*:*
- cpe:2.3:o:zephyrproject:zephyr:3.7.0:-:*:*:*:*:*:*
- cpe:2.3:a:rdkcentral:rdk-b:2024q1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- corp.mediatek.com/product-security-bulletin/November-2025nvdVendor Advisory
News mentions
0No linked articles in our index yet.