MediaTek Flash Tool V5 Out-of-Bounds Read Vulnerability in DA

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in the MediaTek Flash Tool V5, specifically within the DA (Download Agent) component. This issue arises from a missing bounds check, which could lead to local information disclosure. The vulnerability requires physical access to the device for exploitation, and no additional execution privileges are needed. User interaction is also necessary.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information stored on the device.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.3
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.