Description
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
url
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-03.json
Scores
CVSS v3
8.8
EPSS
0.0024
EPSS Percentile
15.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-489
Status
published
Products (1)
Allwinner/H616
Published
Jul 09, 2026
Tracked Since
Jul 09, 2026