The biggest issues are:
CVE-2022-24401 – The Air Interface Encryption (AIE) keystream generator relies on the network time, which is publicly broadcast in an unauthenticated manner. This allows for decryption oracle attacks.
CVE-2022-24402 – The TEA1 algorithm has a backdoor that reduces the original 80-bit key to a key size which is trivially brute-forceable on consumer hardware in minutes.
CVE-2022-24403 – The cryptographic scheme used to obfuscate radio identities has a weak design that allows attackers to de-anonymize and track users.

