Impact
The vulnerability lies in the modem, where improper input validation can cause a system crash. This corresponds to CWE-476, the null pointer dereference flaw. An attacker who can act as a rogue base station—if a user equipment connects to it—can trigger the crash, leading to a denial of service. No elevation of privileges or user interaction is required for exploitation, but the crash disrupts all services dependent on the modem.
Affected Systems
The affected component is the Modem firmware on MediaTek chipsets used in mobile devices. The exact firmware versions prior to the fix are not listed, but any build lacking the patch identified as MOLY01826924 (issue MSV-7301) is potentially vulnerable.
Risk and Exploitability
Exploitability is moderate, as an attacker can act as a rogue base station and send malformed data to the UE without any privileges or user interaction. The CVSS score of 5.3 indicates a moderate impact. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of exploitation in the wild remains low, but the risk to affected devices remains significant.
OpenCVE Enrichment