CVE-2016-10225

HIGH

Allwinner Linux-3.4-sunxi - Access Control

Title source: rule

Description

The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice" to /proc/sunxi_debug/sunxi_debug.

Exploits (1)

metasploit WORKING POC EXCELLENT
by h00die <[email protected]>, KotCzarny · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/local/allwinner_backdoor.rb

Scores

CVSS v3 7.8
EPSS 0.0606
EPSS Percentile 90.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
allwinner/linux-3.4-sunxi
Published Mar 27, 2017
Tracked Since Feb 18, 2026