Impact
This vulnerability exists in MediaTek's Power HAL and arises from a type‑confusion error that can be triggered by a malicious actor who already holds System privilege on the device. The flaw does not require user interaction; once exploited, the attacker can elevate privileges locally to gain higher level control over the system, potentially modifying firmware behavior or accessing sensitive data.
Affected Systems
MediaTek chipsets are affected. No specific firmware or hardware version information is provided in the advisory; all devices using the Power HAL should be evaluated for the presence of the flaw.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, but the absence of an exploitation barrier and the capability to achieve privilege escalation locally indicate a high degree of risk for systems that could already be compromised to System level. The CVSS score is 6.7, so assessment relies on the severity derived from the description and known CWE‑843 type‑confusion weakness.
OpenCVE Enrichment