Impact
Based on the description, it is inferred that the vulnerability is an unchecked memory write in the Modem component that can be triggered when a device receives data from a rogue base station. If adequately exploited, an attacker can corrupt memory and elevate privileges on the device, enabling privileged actions without extra execution rights. This is a classic buffer overflow (CWE-787) and does not require any user interaction.
Affected Systems
The flaw exists in MediaTek chipset Modem firmware. Specific affected firmware versions are not listed, so any device running Mediatek Modem software prior to the release of patch MOLY01402160 remains vulnerable. The patch can be obtained from the MediaTek reference provided
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the EPSS score is < 1%, implying a low but non‑zero probability of exploit. Based on the description, an attacker that can control a rogue base station can trigger the memory corruption without user interaction, enabling privilege escalation on the device. Because the attack can be launched over the air without user interaction and does not require additional privileges, an adversary controlling a rogue base station could leverage this vector. The vulnerability is not currently in CISA’s KEV catalog, but its nature demands urgent remediation.
OpenCVE Enrichment