CVE-2022-32665

CRITICAL

MediaTek LinkIt Software Development Kit < tlb7.3.258.100-p1-1555 - Unauthenticated Remote Command Injection in Boa

Title source: llm
STIX 2.1

Description

In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0185
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
mediatek/linkit_software_development_kit < tlb7.3.258.100-p1-1555
Published Jan 03, 2023
Tracked Since Feb 18, 2026