Impact
An issue in the Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code through the device’s USB debugging (ADB) interface. The vulnerability could compromise the device’s integrity and confidentiality by allowing unauthorized code to run, potentially leading to full device takeover or data exfiltration.
Affected Systems
Only the Code27 Companion Hub model SQ3A.220705.003.A1 is identified as affected; no other versions or vendors are listed. The flaw requires physical proximity to the device’s USB debugging port.
Risk and Exploitability
The CVSS score of 6.8 indicates medium‑to‑high severity, while the EPSS score of < 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires manually connecting a USB cable to the debugging interface, so the risk depends largely on the physical security of the deployment environment. The attack vector is inferred from the description, which states a physically proximate attacker must access the USB debugging port.
OpenCVE Enrichment