CVE-2026-14985 PUBLISHED

CVE-2026-14985

Assigner: certcc
Reserved: 07.07.2026 Published: 22.07.2026 Updated: 22.07.2026

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

Product Status

Vendor Analog Way
Product Picturall Quad Compact Mark II
Versions
  • affected from 3.5.8 to 3.5.9 (excl.)

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-250 Execution with Unnecessary Privileges