Junglewise Threat Intelligence

CVE-2026-14985: Analog Way Picturall Quad Compact Mark II privilege escalation in maintenance script

CVE-2026-14985 · Severity: info · Published 2026-07-22

Executive brief

The Analog Way Picturall Quad Compact Mark II is a high-performance media server used for professional video playback and content management. A security flaw in a maintenance script allows a user with low-level access to gain full administrative control over the device. This could lead to a complete system takeover, allowing an attacker to modify system configurations or disrupt video operations.

Technical details

A local privilege escalation vulnerability exists in the 'create_local_installer.sh' maintenance script of Analog Way Picturall Quad Compact Mark II firmware version 3.5.8. The script is executable by the low-privileged 'picmedia' user via sudo without a password. The script fails to sanitize input from a 'picturall-version.txt' file located on attacker-supplied Ext4 disk images. By using directory traversal sequences in this file, an attacker can perform arbitrary file writes to sensitive system locations such as '/etc/cron.d'. This allows for the execution of arbitrary commands with root privileges, leading to full system compromise. The issue is resolved in version 3.5.9 or via a security hotfix (3.5.8-security1).

Affected products

  • Analog Way Picturall Quad Compact Mark II 3.5.8

Timeline

  • 2026-03-25: other: Vendor notified
  • 2026-07-21: other: Vendor statement issued
  • 2026-07-22: disclosed: Public disclosure via CERT/CC and NVD
  • 2026-07-22: patched: Version 3.5.9 released

References