Description
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.
Published: 2026-07-09
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Allwinner H616 TV Box TV98 ships with the Android Debug Bridge (ADB) enabled and listening on a publicly exposed port. An attacker who can reach this port may request ADB authorization, and if the operator allows the connection the attacker is granted root privileges, allowing arbitrary command execution and full device takeover. The weakness arises from the absence of network‑level access control on ADB, which corresponds to CWE‑489. The vulnerability is limited to devices that expose ADB to the network, but once accessed it enables complete compromise of the operating system.

Affected Systems

All devices running the Allwinner H616 firmware on the TV98 box that have ADB enabled and are reachable from the internet are vulnerable. No specific firmware revision numbers are supplied, so any deployment that has not applied a vendor‑supplied update and still exposes the ADB port is considered at risk.

Risk and Exploitability

The CVSS score of 8.6 classifies the issue as high severity, and the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is straightforward to exploit over the network; the attacker only needs connectivity to the ADB service port, typically 5555, which is inferred to be the attack vector. The vulnerability is not listed in CISA KEV, but the potential to gain root privileges through accepted ADB authorization presents a serious threat to exposed devices.

Generated by OpenCVE AI on July 29, 2026 at 12:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Allwinner firmware update or vendor‑supplied patch that addresses the exposed ADB issue, where available.
  • Configure the network perimeter to block the ADB service port (default 5555) or bind the service to a trusted internal interface so it cannot be reached from the public network.
  • Disable the ADB service over the network on the device itself, or require authentication before enabling ADB, to eliminate the exposed remote debugging capability.
  • Monitor device logs for ADB connection attempts and investigate any unauthorized activity, taking further action if suspicious access is detected.

Generated by OpenCVE AI on July 29, 2026 at 12:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Allwinner
Allwinner h616
Vendors & Products Allwinner
Allwinner h616

Thu, 09 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.
Title Allwinner TV Box TV98 ADB exposed on network
Weaknesses CWE-489
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-07-21T17:05:27.203Z

Reserved: 2026-06-30T15:25:14.279Z

Link: CVE-2026-58378

cve-icon Vulnrichment

Updated: 2026-07-21T17:05:15.333Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:15:03Z

Weaknesses