CVE-2022-32665
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.
Affected (1)
Products: Mediatek: Linkit Software Development Kit
Configuration A
| Running on/with | Platform Versions |
|---|---|
Mediatek En7528 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before tlb7.3.258.100-p1-1555 |
| Running on/with | Platform Versions |
|---|---|
Mediatek En7580 | All versions |
References (2)
Source: security@mediatek.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.