CVE-2022-50935

Severity CVSS v4.0:
HIGH
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
13/01/2026
Last modified:
13/01/2026

Description

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.