CVE-2022-50935: Telcel Flame Ii Modem USB
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.
Affected products
- Telcel Flame Ii Modem USB: affected versions not specified
Published 2026-01-13. Last modified 2026-06-17.