Back to overview

CVE-2026-14985

Description
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

Metadata

CVE ID
CVE-2026-14985
State
PUBLISHED
Assigner
certcc
Reserved
2026-07-07 18:00 UTC
Published
2026-07-22 14:32 UTC
Last updated
2026-07-22 14:32 UTC
Vendor / Product
Analog Way / Picturall Quad Compact Mark II
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Analog Way Picturall Quad Compact Mark II 3.5.8 < 3.5.9
Weakness (CWE)
CWESourceDescription
cna CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
cna CWE-250 Execution with Unnecessary Privileges
Back to overview