Impact
The vulnerability is an out‑of‑bounds write in the MediaTek WiFi driver caused by a missing bounds check, which can lead to local denial of service when an attacker already has system privilege. No user interaction is required for exploitation.
Affected Systems
This issue affects MediaTek chipset products, specifically the WiFi driver on devices powered by MediaTek processors. The precise product list is not detailed in the advisory, but any device using the affected chipset firmware is potentially vulnerable. No specific version numbers are provided, so all current releases carrying the unpatched driver should be considered at risk until a patch is applied.
Risk and Exploitability
The exploit requires that the attacker already possess system privileges; no user interaction is needed and it cannot be triggered remotely. EPSS score is < 1%. The CVSS score is 4.4. The vulnerability is not listed in CISA KEV, indicating no confirmed public exploits yet. While the flaw denies WiFi functionality to the affected device, it does not allow modification of other system resources without additional privileges.
OpenCVE Enrichment