# CVE-2026-58378

## Summary

- **CVE ID:** CVE-2026-58378
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-489
- **Published:** Jul 9, 2026
- **Last Modified:** Jul 21, 2026

## Description

Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.

## Affected Products

- Allwinner — H616 (0)

## References

- [CNA](https://www.cve.org/CVERecord?id=CVE-2026-58378)
- [CNA](https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-03.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 37.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._