Impact
The vulnerability arises from improper input validation in the Modem firmware of MediaTek chipsets (CWE‑476), leading to a system crash. This crash can terminate all services that depend on the modem, effectively causing a denial of service. No user interaction or elevated privileges are required for exploitation.
Affected Systems
The affected component is the Modem firmware on MediaTek chipsets found in mobile devices. Versions that have not incorporated the firmware update containing patch ID MOLY01826924 (issue MSV‑7301) remain vulnerable. Exact firmware build ranges are not specified; any device lacking the patch may be impacted.
Risk and Exploitability
Based on the description, it is inferred that the attack vector requires an attacker to operate a rogue base station which the user equipment connects to. The CVSS score of 5.3 indicates moderate severity, while the EPSS score of < 1 % and the lack of listing in CISA’s KEV catalog suggest a low likelihood of exploitation in the wild. Because no additional privileges are needed, any device that connects to an attacker‑controlled base station can be affected, making this risk significant for organizations that rely on continuous modem availability.
OpenCVE Enrichment