CVE-2016-10225

HIGH

Allwinner linux-3.4-sunxi - Local Privilege Escalation via sunxi_debug Procfs Interface

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-10225. PoCs published by h00die <[email protected]>, KotCzarny, including Metasploit module exploits/multi/local/allwinner_backdoor.

AI-analyzed exploit summary This Metasploit module exploits a debug backdoor in Allwinner SoC devices running Kernel 3.4, allowing local privilege escalation by writing to /proc/sunxi_debug/sunxi_debug. It generates and executes a payload to achieve root access.

Description

The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice" to /proc/sunxi_debug/sunxi_debug.

Exploits (1)

metasploit WORKING POC EXCELLENT
by h00die <[email protected]>, KotCzarny · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/local/allwinner_backdoor.rb

This Metasploit module exploits a debug backdoor in Allwinner SoC devices running Kernel 3.4, allowing local privilege escalation by writing to /proc/sunxi_debug/sunxi_debug. It generates and executes a payload to achieve root access.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Allwinner SoC devices (H3, A83T, H8) with Kernel 3.4
No auth needed
Prerequisites: Access to the target system · Presence of /proc/sunxi_debug/sunxi_debug
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/10/05/16
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2017/02/15/9
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93442
Exploit, Third Party Advisory x_refsource_misc
https://www.rapid7.com/db/modules/exploit/multi/local/allwinner_backdoor
Issue Tracking, Third Party Advisory x_refsource_misc
https://irclog.whitequark.org/linux-sunxi/2016-04-29#16314390

Scores

CVSS v3 7.8
EPSS 0.0395
EPSS Percentile 89.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
allwinner/linux-3.4-sunxi
Published Mar 27, 2017
Tracked Since Feb 18, 2026