Impact
The Analog Way Picturall Quad Compact Mark II firmware version 3.5.8 is vulnerable due to a maintenance script that improperly delegates privileges and fails to validate input correctly, reflecting weaknesses in CWE-22 and CWE-250. The flaw permits a local user to gain higher privileges than intended, effectively creating an escalation path within the device’s operating environment. Such privilege escalation can lead to unauthorized configuration changes, potential persistence mechanisms, or complete compromise of the device’s firmware integrity.
Affected Systems
The affected device is the Analog Way Picturall Quad Compact Mark II. The vulnerability applies to firmware version 3.5.8; no other specific build numbers are identified in the available data.
Risk and Exploitability
The vulnerability is exploitable locally and requires a user to have physical or local access to the device. Because an EPSS score of 0.00174 (less than 1%) is available and the issue is not listed in the CISA KEV catalog, the current exploitation likelihood remains uncertain. Nonetheless, the potential impact of successful privilege escalation is significant, as it could allow an attacker to control the device, modify firmware settings, or establish a foothold for further attacks. The CVSS score of 7.8 indicates high severity, reinforcing the need for prompt attention if the affected firmware version remains in use.
OpenCVE Enrichment