CVE-2026-36433
nicheArbitrary Code Execution in Actions Semiconductor Media Player Utilities 4.46
CVE-2026-36433 is an arbitrary code execution flaw (CWE-94, code injection) in the Production.dll and RdiskUpgrade.exe components of Actions Semiconductor Co. Ltd's Tool - Media Player Utilities version 4.46, a utility used to service and upgrade firmware on Actions Semiconductor-based media players. According to the description, a physically proximate attacker can trigger the issue through these components to run arbitrary code, although the advisory is scored 9.8 (critical) with a network attack vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation gives the attacker arbitrary code execution under the privileges of the user running the utility, potentially compromising the workstation and any connected player being flashed or produced. Affected parties are anyone running Tool - Media Player Utilities 4.46, typically device manufacturers, refurbishers, and repair technicians who use the flashing/upgrade tooling. There are no reports of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Inventory Windows workstations where Tool - Media Player Utilities 4.46 is installed, and restrict use of Production.dll and RdiskUpgrade.exe to trusted, dedicated flashing/upgrade machines until a patched release is available from Actions Semiconductor. Because the trigger is described as physically proximate, limiting physical access to machines running the tool and avoiding use of the utility on shared or publicly accessible systems reduces exposure. Monitor the vendor and MITRE for a fixed version, since none is stated in the advisory.
| Actions Semiconductor Co. Ltd Tool - Media Player Utilities | 4.46 (the only version named in the advisory; no fixed version or other affected ranges are provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.