Impact
The flaw allows a crafted SQLite file name to be concatenated with an operating‑system shell command without proper escaping. This results in OS command injection, which can give an attacker the ability to execute arbitrary code with the privileges of the application. The core weakness is input validation, as described by CWE‑78, and the attack can compromise both the confidentiality and integrity of the device.
Affected Systems
Maple Media Root Browser Classic version 3.3.0 for Android. This is the only product and version explicitly listed in the advisory.
Risk and Exploitability
The vulnerability carries a high CVSS score of 8.5 and is not listed in the CISA KEV catalog, indicating it is not a known exploited vulnerability. The EPSS score is not available, so exploitation probability cannot be precisely quantified, but the absence of a KEV listing suggests it may not be actively exploited yet. The vulnerability requires a user to create a SQLite file with a malicious name and then open it in the application, implying a local or semi‑local attack vector where the adversary has file‑write access on the device.
OpenCVE Enrichment