Impact
The vulnerability is a missing bounds check in MediaTek modem firmware that can cause an unexpected system crash. An attacker controlling a rogue base station can trigger the flaw by sending specially crafted traffic, leading to a denial‑of‑service state for the user equipment. No additional privileges or user interaction are required.
Affected Systems
MediaTek chipsets—including the MT2735, MT2737, MT6813, MT6815, MT6833, MT6835, MT6853, MT6855, MT6858, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6983, MT6985, MT6986, MT6989, MT6990, MT6991, MT6993, MT8668, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8791, MT8791t, MT8792, MT8793, MT8795t, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893 and the NR5G platforms NR15, NR16, NR17, NR17r
Risk and Exploitability
The CVSS base score of 6.5 reflects moderate severity. The EPSS score is below 1 %, indicating a very low expected exploitation probability at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely by connecting a UE to a malicious base station that sends out a malformed packet causing the modem to crash. Because user interaction is not required, it could be abused in mass‑scale denial‑of‑service attacks against affected devices.
OpenCVE Enrichment