In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418044; Issue ID: MSV-3482.
Cite this page
CVE-2025-20680. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-20680
Use CWE-122, Mediatek vendor hub and Nbiot Sdk product page to widen CVE-2025-20680 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-26437, CVE-2026-20407 and CVE-2026-20423 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 6th, 2026.