Impact
The vulnerability is an improper validation of external input in the MediaTek, Inc. chipsets (CWE‑288). This flaw allows an attacker to inadvertently glean information from the device, enabling remote data disclosure. The flaw does not require execution privileges or user interaction, and the impact is limited to confidentiality breach.
Affected Systems
MediaTek, Inc. chipsets that include the Modem are not disclosed, so any device using the vulnerable Modem functionality is potentially at risk.
Risk and Exploitability
The likely attack vector is that an attacker can establish a base‑station link to the victim device without requiring privileged access or user interaction. The attack requires only that the device connect to a malicious base station. The low EPSS score (< 1 %) probability of exploitation in the wild, yet the relative ease of triggering and the confidentiality impact warrant vigilance. The CVSS score of 5.3 reflects a moderate impact on confidentiality, and the vulnerability is not currently in the CISA KEV catalog.
OpenCVE Enrichment