Impact
This vulnerability is a missing bounds check in the modem firmware that can cause the system to crash. The flaw leads to remote denial of service, providing attackers the ability to disrupt service without executing arbitrary code or requiring elevated privileges. The weakness is identified as input validation failure (CWE-617).
Affected Systems
MediaTek chipset products are affected. No specific firmware versions are listed, so all current releases until a patch is applied should be considered at risk.
Risk and Exploitability
The exploit can be triggered by connecting a user equipment device to a rogue base station controlled by the attacker; user interaction is not needed. The CVSS score is 5.3, indicating moderate severity. Because the CVE source does not provide an EPSS score, the historical exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via the wireless interface, and the lack of an EPSS score means defenders should treat this as a potentially high-risk threat, especially in environments where devices may encounter untrusted base stations.
OpenCVE Enrichment