Impact
A missing bounds check in the modem firmware allows an out‑of‑bounds write that can corrupt memory. This flaw is identified as CWE-787. The corruption can be triggered remotely through the radio interface, so no user interaction or elevated privileges are required. The likely effect is a service interruption for the device, manifesting as a denial of service for user equipment that connects to an attacker‑controlled base station.
Affected Systems
MediaTek, Inc. chipsets are affected. The vendor advisory does not disclose specific model or firmware revision numbers, but the issue can be addressed with the firmware updates provided under patch IDs MOLY01267281 or MOLY01318201.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% points to a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by operating a rogue base station; when user equipment connects, the out‑of‑bounds write is triggered and the modem can be brought to a non‑responsive state.
OpenCVE Enrichment