Impact
The vulnerability is an out‑of‑bounds read caused by a missing bounds check in the geniezone firmware component. An attacker that already holds system privileges can read memory beyond intended bounds and obtain sensitive local data. The exploit can be performed without any user interaction.
Affected Systems
The affected products are MediaTek chipsets that include the geniezone component. No specific firmware or hardware revision numbers are listed in the advisory, so any MediaTek chipset with the vulnerable geniezone firmware is considered at risk.
Risk and Exploitability
The vulnerability requires an attacker to have system privilege before exploitation, limiting it to local attacks. An EPSS score of < 1% indicates a low probability of exploitation, and the issue is not in the CISA KEV catalog, indicating no known active exploits at this time. With a CVSS score of 4.4, the severity is moderate but still allows potential leakage when privilege escalation occurs.
OpenCVE Enrichment