Impact
The Allwinner H616 TV Box TV98 ships with the Android Debug Bridge (ADB) enabled and listening on a publicly exposed port. An attacker who can reach this port may request ADB authorization, and if the operator allows the connection the attacker is granted root privileges, allowing arbitrary command execution and full device takeover. The weakness arises from the absence of network‑level access control on ADB, which corresponds to CWE‑489. The vulnerability is limited to devices that expose ADB to the network, but once accessed it enables complete compromise of the operating system.
Affected Systems
All devices running the Allwinner H616 firmware on the TV98 box that have ADB enabled and are reachable from the internet are vulnerable. No specific firmware revision numbers are supplied, so any deployment that has not applied a vendor‑supplied update and still exposes the ADB port is considered at risk.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity, and the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is straightforward to exploit over the network; the attacker only needs connectivity to the ADB service port, typically 5555, which is inferred to be the attack vector. The vulnerability is not listed in CISA KEV, but the potential to gain root privileges through accepted ADB authorization presents a serious threat to exposed devices.
OpenCVE Enrichment