CVE-2025-20649
MEDIUMDescription
In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.
Is your site exposed to CVE-2025-20649?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mediatek | software_development_kit |
| openwrt | openwrt |
| mediatek | mt6880 |
| mediatek | mt6890 |
| mediatek | mt6980 |
| mediatek | mt6990 |
| mediatek | mt7663 |
| mediatek | mt7902 |
| mediatek | mt7925 |
| mediatek | mt7927 |
| mediatek | mt7961 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-20649? +
How severe is CVE-2025-20649? +
What products are affected by CVE-2025-20649? +
How do I check if I'm vulnerable to CVE-2025-20649? +
Related Vulnerabilities
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended …
When creating an export of all reusable media, the secrets of connected gift cards were included in the export even …
An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated …
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass …
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to …
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.