Impact
The vulnerability arises from a missing bounds check in the modem firmware of MediaTek chipsets. An attacker can trigger a system crash by sending specially crafted data, causing the modem process to terminate. The crash manifests as a denial of service, denying normal network functions to the user device.
Affected Systems
Affected products include a broad range of MediaTek hardware, such as MT2735, MT2737, MT6813, MT6815, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6983, MT6985, MT6989, MT6990, MT6991, MT6993, MT8673, MT8675, MT8676, MT8771, MT8791, MT8791t, MT8795t, MT8797, MT8798, MT8893, as well as various networking modules (e.g., NR15, NR16, NR17, NR17r). The vendor has issued firmware patch IDs MOLY01689254 for N15 and NR16 devices and MOLY01689259 for NR17 and NR17R devices.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity, while the EPSS score is less than 1 % showing a low probability of exploitation. The vulnerability is not present in the CISA KEV catalog. An attacker can exploit this by remotely sending malformed data to the modem, for example from a rogue base station that a user device connects to. No user interaction and no extra privileges are required, making the attack vector purely remote network based.
OpenCVE Enrichment