Impact
The vulnerability is an out‑of‑bounds write caused by an incorrect bounds check in MediaTek’s firmware. An attacker with local execution privileges could trigger the write, resulting in a denial of service on the affected chipsets. The flaw does not require user interaction beyond the privilege level needed to execute code.
Affected Systems
MediaTek chipsets are impacted: models MT6890, MT6990, and MT6988 are fixed by patch ALPS10981478, while MT2735 and MT2737 are resolved by patch AUTO00851173. No specific firmware or version range is listed, but the referenced patch IDs apply to those device families.
Risk and Exploitability
Risk assessment shows an EPSS score of < 1% and no KEV listing; the CVSS score is 5.5, indicating medium severity. Because the exploit requires local execution privileges and no remote triggering, the likelihood of exploitation is low, but local attackers could cause a denial of service interrupting device operation. No publicly known exploits exist, so the current risk remains moderate until the patch is applied.
OpenCVE Enrichment