VYPR

QCMAP_CLI

by Qualcomm

CVEs (1)

  • CVE-2020-25859MedOct 15, 2020
    risk 0.44cvss 6.7epss 0.00

    The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validating the input, while handling a SetGatewayUrl() request. A local attacker with shell access can pass shell metacharacters and run arbitrary…