CVE Vulnerabilities

CVE-2025-20730

Improper Authentication

Published: Nov 04, 2025 | Modified: Nov 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Yocto Linuxfoundation 4.0 (including) 4.0 (including)
Rdk-b Rdkcentral 2024q1 (including) 2024q1 (including)
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)
Android Google 15.0 (including) 15.0 (including)
Android Google 16.0 (including) 16.0 (including)
Openwrt Openwrt 21.02.0 (including) 21.02.0 (including)
Openwrt Openwrt 23.05.0 (including) 23.05.0 (including)

Potential Mitigations

References