Impact
The vulnerability resides in the modem component of MediaTek chipsets and arises from improper input validation. Maliciously crafted input can trigger a system crash, resulting in a remote denial of service. The attack requires no user interaction and does not grant additional privileges, meaning any device that connects to a rogue base station under attacker control can be impacted.
Affected Systems
MediaTek, Inc. MediaTek chipset devices. Specific model or firmware versions are not enumerated in the advisories.
Risk and Exploitability
The risk includes remote DoS for devices that have established a link with a rogue base station. Since user interaction or elevated privileges are not required, the attack surface is broad. Except for MediaTek's patch, the exploit is straightforward. The known EPSS score is unavailable and the vulnerability is not listed in KEV, but given the high impact of a DoS, it should be treated as a serious threat.
OpenCVE Enrichment