Vulnerability Description
In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mediatek | Linkit Software Development Kit | < tlb7.3.258.100-p1-1555 |
| Mediatek | En7528 | - |
| Mediatek | En7580 | - |
Related Weaknesses (CWE)
References
- https://corp.mediatek.com/product-security-bulletin/January-2023Vendor Advisory
- https://corp.mediatek.com/product-security-bulletin/January-2023Vendor Advisory
FAQ
What is CVE-2022-32665?
CVE-2022-32665 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is no...
How severe is CVE-2022-32665?
CVE-2022-32665 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-32665?
Check the references section above for vendor advisories and patch information. Affected products include: Mediatek Linkit Software Development Kit, Mediatek En7528, Mediatek En7580.