Impact
An error handling flaw in the modem component can trigger an out‑of‑bounds memory read (CWE‑125), leading to a system crash. The crash results in a denial of service that does not grant an attacker any execution privileges or require user interaction. The vulnerability is limited to the modem but can potentially disrupt the entire device’s network connectivity.
Affected Systems
The issue affects MediaTek’ s chipset family, including models MT2735, MT2737, MT6813, MT6815, MT6833, MT6835, MT6853, MT6855, MT6858, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6983, MT6985, MT6986, MT6989, MT6990, MT6991, MT6993, MT8676, MT8791, as well as the NR15, NR16, NR17 and NR17R firmware lines.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of active exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit it remotely by connecting a user equipment to a rogue base station; no additional privileges or user interaction are needed, making the attack path straightforward for a determined adversary.
OpenCVE Enrichment