CVE-2022-26437
Status: ModifiedCritical (9.8)—
In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.41%
- Percentile among all scored CVEs: 72
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-908
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-26437",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@mediatek.com",
"affectedData": [
{
"vendor": "MediaTek, Inc.",
"product": "MT2621, MT2625",
"versions": [
{
"status": "affected",
"version": "NBIOT SDK V2.8.1"
}
]
}
]
}
],
"published": "2022-08-01T14:15:09.493",
"references": [
{
"url": "https://corp.mediatek.com/product-security-bulletin/August-2022",
"tags": [
"Vendor Advisory"
],
"source": "security@mediatek.com"
},
{
"url": "https://corp.mediatek.com/product-security-bulletin/August-2022",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-908"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831."
},
{
"lang": "es",
"value": "En httpclient, se presenta una posible escritura fuera de límites debido a datos no inicializados. Esto podría conllevar a una escalada remota de privilegios sin necesidad de privilegios de ejecución adicionales. No es requerida una interacción del usuario para su explotación. ID del Parche: WSAP00103831; ID de Incidencia: WSAP00103831"
}
],
"lastModified": "2026-06-17T04:35:11.743",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mediatek:nbiot_sdk:2.8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A839D4B-4B20-4663-A018-63F6CF6D840B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:mediatek:mt2621:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D22D1E86-2AD6-4B60-9E87-C309F928C579"
},
{
"criteria": "cpe:2.3:h:mediatek:mt2625:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DF1AF8D8-F68E-4697-9E7A-8CDA6899F643"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@mediatek.com"
}