CVE-2022-26580
Summary
| CVE | CVE-2022-26580 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-16 22:15:00 UTC |
| Updated | 2023-03-01 00:15:00 UTC |
| Description | PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the device in order to exploit this vulnerability. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Paxtechnology | A930 | - | All | All | All |
| Operating System | Paxtechnology | Paydroid | 7.1.1_virgo_v04.3.26t1_20210419 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cyshield | MISC | cyshield.com | |
| PAX-Paydroid-Advisories/CVE-2022-26580.md at master · wr3nchsr/PAX-Paydroid-Advisories · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.