First published: Tue Jan 03 2023(Updated: )
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Patch ID: A20220004; Issue ID: OSBNB00140929.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mediatek Linkit Software Development Kit | <7.3.293.0 | |
Mediatek En7516 | ||
Mediatek En7528 Firmware | ||
MediaTek En7529 | ||
Mediatek En7561 | ||
Mediatek En7562 | ||
Mediatek En7580 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32664 has a potential impact resulting in remote escalation of privilege due to command injection.
To fix CVE-2022-32664, apply the patch identified by Patch ID A20220004.
CVE-2022-32664 is caused by improper input validation in Config Manager.
CVE-2022-32664 affects versions of the Mediatek Linkit Software Development Kit up to 7.3.293.0.
Yes, user interaction is necessary for successful exploitation of CVE-2022-32664.