Impact
A missing bounds check in the Thread implementation of MediaTek chipsets allows an adversary to perform an out‑of‑bounds write. This flaw can be triggered remotely and leads to escalation of privileges without the need for additional execution rights. The weakness is identified as a buffer overrun (CWE‑787).
Affected Systems
The vulnerability affects MediaTek devices that incorporate the MT7931 or MT7933 chipsets, components commonly used in Internet of Things appliances. It may also impact systems that rely on these chipsets for Matter‑based connectivity. Only the specified hardware revisions are known to be susceptible.
Risk and Exploitability
The CVSS base score is 9.8, indicating critical severity. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, as no user interaction is required for exploitation, and the flaw permits privilege escalation immediately upon a successful out‑of‑bounds write.
OpenCVE Enrichment