Impact
The vulnerability is an improper validation of input in the Modem component, allowing unauthorized disclosure of information from the device. It does not require execution privileges or user interaction, and its impact is limited to a breach of confidentiality.
Affected Systems
MediaTek, Inc. chipsets that include the Modem component versions are not listed, but any device that incorporates the vulnerable Modem firmware is potentially impacted.
Risk and Exploitability
The likely attack vector is that an attacker can establish a base‑station link to the victim device so the device connects to a malicious base station. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, yet the relative ease of triggering and the confidentiality impact warrant vigilance. The CVSS score of 5.3 indicates a moderate impact on confidentiality, and the vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment