MediaTek MT2735
cpe:2.3:h:mediatek:mt2735:*:*:*:*:*:*:*, +1 more
- NR15
- NR16
- NR17
- NR17R
A high-severity out-of-bounds write vulnerability has been identified in the Modem component of various MediaTek chipsets. This issue arises from an incorrect bounds check, which could allow remote privilege escalation. The vulnerability can be exploited if a user equipment (UE) connects to a rogue base station controlled by an attacker. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.
Exploitation of this vulnerability could lead to unauthorized privilege escalation on the affected device.
MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. Instructions for applying the patch are available through MediaTek's official channels.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.