Alcatel Flame II HSPA USB Modem Unquoted Service Path Vulnerability

Vulnerability

A vulnerability exists in the Alcatel Flame II HSPA USB Modem due to an unquoted service path in its Windows service configuration. This flaw allows attackers to exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with elevated privileges on the affected system.

Reproduction

The vulnerability can be reproduced by creating a service with an unquoted path that includes spaces. This can be done using the Windows Service Control (sc) command. Once the service is created, it can be started, and the unquoted path will be used to execute the application, allowing for code execution with elevated privileges.

Added: Jan 13, 2026, 11:58 PM
Updated: Jan 13, 2026, 11:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.