Impact
A heap buffer overflow exists in the wlan Access Point driver of MediaTek chipsets, enabling memory corruption. This flaw can be triggered without user interaction and may result in remote code execution on the device at the privilege level of the executing user. The vulnerability is a classic buffer overflow (CWE-122), potentially compromising confidentiality, integrity, and availability if exploited.
Affected Systems
The flaw affects MediaTek chipsets' WLAN AP driver. No specific version numbers are listed, so any firmware that includes the vulnerable driver may be impacted.
Risk and Exploitability
Both the CVSS score and EPSS score are not disclosed, but the vulnerability is a heap buffer overflow that allows remote code execution without user interaction. Because the flaw is not listed in CISA KEV it has not yet been reported as an active exploit, however the nature of the defect and the lack of user interaction make it a high‑risk threat; an attacker who can send crafted frames to the device could compromise confidentiality, integrity, and availability of the WLAN AP.
OpenCVE Enrichment