Impact
The vulnerability is an improper input validation flaw in MediaTek modem firmware that can cause the system to crash. Exploitation leads to a remote denial of service; the attacker does not need user interaction or elevated privileges. The weakness is classified as CWE-787, indicating a possible out-of-bounds write or similar memory corruption.
Affected Systems
The flaw affects MediaTek, Inc. media chipset devices that include the listed hardware models such as MT2735, MT2737, MT6813, MT6815, MT6833, MT6835, MT6853, MT6855, MT6858, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6983, MT6985, MT6986, MT6989, MT6990, MT6991, MT6993, MT8668, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8791, MT8791t, MT8792, MT8793, MT8795t, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893 and the NR5G platforms NR15 through NR17r. No specific firmware version ranges are provided, so all affected releases should be considered at risk until patched.
Risk and Exploitability
CVSS v3.1 score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit path is via a rogue base station that a user equipment (UE) connects to, requiring no user interaction or elevated privileges. Because the attacker can trigger a denial of service remotely, carriers and manufacturers should treat this as a moderate risk until the official patch is applied.
OpenCVE Enrichment