Impact
The vulnerability is a CWE‑288 problem caused by improper input validation in the Modem firmware of MediaTek chipsets, which allows malformed data from a connected user equipment to trigger a crash. This crash results in a remote denial of service, interrupting normal device operation. The weakness corresponds to an improper authority validation that leads to a software failure and complies with the denial‑of‑service condition described by CWE‑288.
Affected Systems
All MediaTek chipset devices that include the vulnerable Modem enumerated; therefore any device running the unpatched firmware could be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity impact. Exploitation requires the attacker to operate a rogue base station that transmits crafted data to the device. The vulnerability is not listed in the CISA KEV catalog. The attack surface is limited to connections over the radio interface used by the modem, without the need for further system access. The EPSS score indicates a very low exploitation probability, less than 1%.
OpenCVE Enrichment