Impact
Based on the description, this vulnerability is an unchecked memory write in the Modem component that can be triggered when a device receives data from a rogue base station. If adequately exploited, an attacker can corrupt memory and elevate privileges on the device, enabling privileged actions without extra execution rights. This is a classic buffer overflow (CWE-787) and does not require any user interaction.
Affected Systems
The flaw exists in MediaTek chipset Modem firmware. Specific the MOLY01402160 is applied. The patch can be obtained from the MediaTek reference provided.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the EPSS score is < 1%, implying a low but non‑zero probability of exploitation. Because the attack can be launched over the air without user interaction and does not require additional privileges, an adversary controlling a rogue base station could leverage this vector. The vulnerability is not currently in CISA’s KEV catalog, but its nature demands urgent remediation.
OpenCVE Enrichment