CVE-2022-26437

CRITICAL

MediaTek NBIoT SDK httpclient - Out-of-Bounds Write Remote Privilege Escalation

Title source: manual
STIX 2.1

Description

In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0145
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-908
Status published
Products (1)
mediatek/nbiot_sdk 2.8.1
Published Aug 01, 2022
Tracked Since Feb 18, 2026