Impact
An authenticated attacker can exploit an Unquoted Search Path flaw (CWE-428) in NetKids iMark to launch arbitrary code with SYSTEM privileges, giving full control over the device and compromising confidentiality, integrity, and availability.
Affected Systems
The vendor Integrated Systems Technologies, Inc. supplies the NetKids iMark product. No version information has been disclosed, so all released versions should be considered potentially vulnerable until a fix is deployed.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, reflecting a high impact. EPSS data is not available, and the flaw is not listed in CISA KEV. Exploitation requires authenticated access, likely through legitimate credentials, after which the attacker can manipulate the unquoted search path to execute system binaries with full privileges.
OpenCVE Enrichment