Command Injection Vulnerability in MediaTek Config Manager
CVE-2022-32664
8.8HIGH
Key Information:
- Vendor
- MediaTek
- Vendor
- CVE Published:
- 3 January 2023
Summary
In MediaTek's Config Manager, a command injection vulnerability exists due to insufficient input validation. This could potentially allow an attacker to escalate user privileges remotely, but it requires user interaction to exploit. Affected users are urged to apply patch A20220004 to mitigate the risk associated with this vulnerability.
Affected Version(s)
EN7516, EN7528, EN7529, EN7561, EN7562, EN7580 Linux SDK versions less than TLM-7.3.293.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved