Impact
The vulnerability resides in the WLAN STA firmware of MediaTek chipsets, where excessive or unbounded logging can cause the system to become unresponsive. This results in a denial‑of‑service condition that can be triggered remotely from a nearby or adjacent source without requiring any additional privileges or user interaction. The weakness corresponds to CWE‑770, representing failure to control memory or resource consumption.
Affected Systems
The affected products are MediaTek chipsets running the WLAN STA firmware. No specific firmware versions are listed in the provided data, so all current releases that include the vulnerable logging mechanism are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a somewhat lower likelihood of exploitation. However, the attack vector is remote (proximal/adjacent) and no credentials are required, making it accessible to any nearby device. Because the impact is a complete denial of service, the risk to availability is high, and a timely patch is strongly recommended.
OpenCVE Enrichment