CVE-2026-14985

Summary

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

Affected Software

VendorProductVersion RangeStatus
Analog WayPicturall Quad Compact Mark II3.5.8 < 3.5.9affected

Weaknesses

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-250 Execution with Unnecessary Privileges

References