VYPR

Linkit Software Development Kit

by Mediatek

CVEs (3)

  • CVE-2022-32665CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.02

    In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.

  • CVE-2021-30636CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc.

  • CVE-2022-32664HigJan 3, 2023
    risk 0.57cvss 8.8epss 0.01

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Patch ID: A20220004; Issue ID: OSBNB00140929.