CVE-2022-38691

HIGH

Unisoc SC9863A/T310/T610/T618 - Local Privilege Escalation via BootROM Certificate Type Validation Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-38691. PoCs published by TomKing062.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2022-38691, which involves manipulating firmware image headers and certificates to bypass security checks in Spreadtrum (Unisoc) trusted firmware. The code modifies the firmware structure to exploit vulnerabilities in the signature verification process.

Description

In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed.

Exploits (1)

nomisec WORKING POC 89 stars
by TomKing062 · poc
https://github.com/TomKing062/CVE-2022-38691_38692

This repository contains a functional exploit PoC for CVE-2022-38691, which involves manipulating firmware image headers and certificates to bypass security checks in Spreadtrum (Unisoc) trusted firmware. The code modifies the firmware structure to exploit vulnerabilities in the signature verification process.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Spreadtrum (Unisoc) trusted firmware
No auth needed
Prerequisites: Access to the target firmware image · Configuration file with specific parameters
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0033
EPSS Percentile 24.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-250
Status published
Products (1)
Unisoc (Shanghai) Technologies Co., Ltd./SC9863A//T310/T610/T618/ /
Published Sep 01, 2025
Tracked Since Feb 18, 2026