Impact
A missing bounds check in the modem firmware permits an out‑of‑bounds write that can corrupt memory (CWE-787). No user interaction or elevated privileges are required for exploitation.
Affected Systems
MediaTek, Inc. chipsets are affected. Specific model or firmware revision numbers are not disclosed by the vendor advisory.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, while the EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not present in the CISA KEV catalog. Attackers could exploit the flaw remotely using the radio interface; a rogue base station can trigger the out‑of‑bounds write whenever user equipment establishes a connection.
OpenCVE Enrichment