{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/360868#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\n\r\nVersion 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script.\r\n\r\n### Description\r\n\r\nThe Picturall Quad Compact Mark II is a compact, heavy-duty 8K media server developed by Analog Way for video playback and content management in professional audiovisual environments.\r\n\r\nThe core firmware includes a maintenance script called `create_local_installer.sh`, and the default script permission allows the low-privileged user, `picmedia`, to execute it as root and without a password. An attacker creates a malicious Ext4 disk image that contains the file, `picturall-version.txt`, with a directory traversal string and a payload file. `create_local_installer.sh` reads input from `picturall-version.txt` when processing these attacker-supplied disk images. This input is not properly sanitized, allowing an attacker to supply directory traversal sequences. As a result, the attacker can manipulate the script to write files outside of the intended extraction directory and execute a malicious payload.\r\n\r\nBecause the script executes with root privileges, this behavior enables arbitrary file writes to sensitive system locations such as `/etc/cron.d, a system directory in Unix/Linux operating system used to store system-wide task scheduling files. An attacker can then leverage this capability to execute arbitrary code with root privileges.\r\n\r\n### Impact\r\n\r\nBy exploiting this path traversal vulnerability, an attacker with local access to the device can write arbitrary files to privileged locations. This access allows modification of scheduled tasks, and system configuration files. It can also allow the execution of a[RM2.1][MB2.2]rbitrary commands with full system privileges.\r\n\r\nAn attacker does not need valid root credentials to enable straightforward and repeatable exploitation, resulting in complete system compromise.[RM3.1][MB3.2] This constitutes a *Technical Impact = Total* under the [SSVC](https://certcc.github.io/SSVC/reference/decision_points/technical_impact/) framework, meaning:\r\n> The vulnerability gives the adversary total control over the behavior of the software or total disclosure of all information on the affected system.\r\n\r\n### Solution\r\n\r\nAnalog Way has released version 3.5.9 to address this vulnerability. Users are strongly encouraged to update to the fixed release as soon as possible. \r\n\r\n### Acknowledgements\r\n\r\nThanks to the reporter James Tully for responsibly disclosing this issue. This document was written by Michael Bragg.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"},{"category":"other","text":"Analog Way confirms that all Picturall media server products are affected by this vulnerability.\r\n\r\nThe fix is included in Picturall software version 3.5.9, a full public release now available as a firmware download from the Analog Way website; customers are advised to update to 3.5.9.\r\n\r\nCustomers who require a security-only fix without other changes can instead request the hotfix (version 3.5.8-security1) from Analog Way technical support at techsupport@analogway.com.","title":"Vendor statment from Analog Way"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/360868"}],"title":"Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability","tracking":{"current_release_date":"2026-07-22T14:30:26+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.43"}},"id":"VU#360868","initial_release_date":"2026-07-22 14:30:26.405676+00:00","revision_history":[{"date":"2026-07-22T14:30:26+00:00","number":"1.20260722143026.1","summary":"Released on 2026-07-22T14:30:26+00:00"}],"status":"final","version":"1.20260722143026.1"}},"vulnerabilities":[{"title":"The Analog Way Picturall Quad Compact Mark II version 3.","notes":[{"category":"summary","text":"The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script."}],"cve":"CVE-2026-14985","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#360868"}],"product_status":{"known_affected":["CSAFPID-b92cd876-85f2-11f1-8698-0affeea5efbd"]}}],"product_tree":{"branches":[{"category":"vendor","name":"Analog Way","product":{"name":"Analog Way Products","product_id":"CSAFPID-b92cd876-85f2-11f1-8698-0affeea5efbd"}}]}}