Impact
The vulnerability is an out‑of‑bounds write in the WLAN access point driver caused by a missing bounds check. This flaw can be exploited to gain elevated privileges on the device without any additional execution rights and without user interaction. It represents typical memory corruption that could allow an attacker to modify privileged data structures and take control of the device.
Affected Systems
Vendors affected include MediaTek, Inc., specifically the MediaTek chipset family. No specific processor/firmware versions are listed in the advisory, so any device using the vulnerable driver version is potentially impacted.
Risk and Exploitability
The exploit requires proximity or adjacency to the device and no user interaction. EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting documented exploitation has not yet been observed. Nevertheless, the missing bounds check indicates a high potential for privilege escalation, and the CVSS base score is 8.1, reflecting the severity of the flaw. Attackers would need local or adaptive network access to the affected Wi‑Fi driver to leverage the vulnerability.
OpenCVE Enrichment