peter bassill · operator
$ cve CVE-2022-21744 JSON

CVE-2022-21744

9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00810064; Issue ID: ALPS06641626.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.44% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2022-07-06
Last modified2026-06-17

Affected (40)

VendorProduct
mediateklr11
mediateklr12
mediateklr12a
mediateklr13
mediateklr9
mediatekmt2731
mediatekmt2735
mediatekmt6297
mediatekmt6725
mediatekmt6735
mediatekmt6737
mediatekmt6739
mediatekmt6750
mediatekmt6750s
mediatekmt6755
mediatekmt6757
mediatekmt6757p
mediatekmt6758
mediatekmt6761
mediatekmt6762
mediatekmt6762d
mediatekmt6762m
mediatekmt6763
mediatekmt6765
mediatekmt6765t
mediatekmt6767
mediatekmt6768
mediatekmt6769
mediatekmt6769t
mediatekmt6769z
mediatekmt6771
mediatekmt6775
mediatekmt6779
mediatekmt6781
mediatekmt6783
mediatekmt6785
mediatekmt6785t
mediatekmt6789
mediateknr15
mediateknr16

References

→ the Explorer  ·  watch your stack  ·  NVD