# FLAME II MODEM USB 服务路径漏洞
N/A
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: FLAME II MODEM USB - Unquoted Service Path - Windows local Exploit -- 🔗来源链接
标签:exploit
神龙速读:
- **EDB-ID:** 50708
- **CVE:** N/A
- **Author:** Ismael Nava
- **Type:** LOCAL
- **Platform:** WINDOWS
- **Date:** 2022-02-04
- **Vulnerability Summary:**
- **Title:** FLAME II MODEM USB - Unquoted Service Path
- **Discovery by:** Ismael Nava
- **Discovery Date:** 02-02-2022
- **Vendor Homepage:** https://www.telcel.com/personas/equipos/modems-usb/alcatel/x602a
- **Software Links:** N/A (Is a BAM)
- **Tested Version:** N/A
- **Vulnerability Type:** Unquoted Service Path
- **Tested on OS:** Windows 10 64 BITS
- **Vulnerability Details:**
- **wmic service get name, displayname, pathname, startmode | findstr /i "Auto" | findstr /i /v "C:\Windows\\\" | findstr /i /v \"""
- **Service Name:** FLAME II HSPA USB MODEM Service
- **Display Name:** FLAME II HSPA USB MODEM Service
- **Path Name:** C:\Program Files (x86)\Internet Telcel\ApplicationController.exe
- **Start Mode:** Auto
- **NOMBRE_INICIO_SERVICIO:** LocalSystem
标题: FLAME II MODEM USB - Unquoted Service Path | Advisories | VulnCheck -- 🔗来源链接
标签:third-party-advisory
神龙速读:
### 关键漏洞信息
#### 漏洞名称
- **FLAME II MODEM USB - Unquoted Service Path**
#### 严重性
- **High**
#### 发布日期
- January 13, 2026
#### 影响范围
- **FLAME II MODEM USB Unknown**
#### CVE 号
- CVE-2022-50935
#### Unquoted Service Path
- AnquPAN4.6.3-CWE-428 Unquoted Search Path or Element
#### exploitdb 号
- exploitDB-50708
#### 归档页面
- Archived Telcel Flame II MODEM USB Product Page
#### 发现者
- Ismael Nava
#### 描述
- Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.