CVE-2022-50935: Telcel Flame Ii Modem USB

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

Affected products

  • Telcel Flame Ii Modem USB: affected versions not specified

Published 2026-01-13. Last modified 2026-06-17.