Impact
A missing bounds check in the MediaTek WLAN STA driver can cause a system crash, leading to local denial of service. The flaw, identified as CWE‑787, requires that the attacker possess user‑level execution privileges to trigger the crash. No user interaction beyond local execution is needed, and the vulnerability cannot be leveraged remotely.
Affected Systems
Devices powered by MediaTek chipsets are affected. The patch ID WCNCR00480851 is associated with this vulnerability, but no specific firmware or kernel versions are disclosed; any device incorporating the vulnerable WLAN driver should be evaluated for the presence of the patch.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity attack. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation. Because the attack vector is local and requires user privileges, only individuals with physical or local console access can trigger the denial of service. Although the flaw does not present a remote vector, its ability to crash the system makes it a significant local risk.
OpenCVE Enrichment