CVE-2026-58378
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.44%
- CWE
- CWE-489
- Published
- 2026-07-09
- Last modified
- 2026-07-21
Affected products
- Allwinner H616
Weakness type
Related vulnerabilities
- CVE-2026-6485 — UEFI BIOS embedded Shell can be used to bypass Secure Boot
- CVE-2026-77545 — A malicious actor with access to the network, low privileges and under certain conditions could...
- CVE-2026-66787 — Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082
- CVE-2026-66405 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be...
- CVE-2026-66403 — DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor...
- CVE-2026-41186 — Unauthenticated Go pprof exposure in Calico debug server
- CVE-2026-65893 — Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
- CVE-2026-54799 — A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...