Описание
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition.
The attacker must have physical USB access to the device in order to exploit this vulnerability.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Permissions Required
- ExploitThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Permissions Required
Уязвимые конфигурации
Одновременно
Одновременно
EPSS
6.8 Medium
CVSS3
Дефекты
Связанные уязвимости
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition. The attacker must have physical USB access to the device in order to exploit this vulnerability.
Уязвимость операционной системы PayDroid, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю выполнить произвольный код
EPSS
6.8 Medium
CVSS3