Executive brief
The E-Gate Atom 3X is an Android-based smart projector used for multimedia displays. A security flaw allows anyone on the same Wi-Fi or local network to connect to the device's management interface without a password. This could allow an attacker to take full control of the projector, access stored data, or disrupt its operation.
Technical details
The vulnerability is a case of missing authentication for a critical function (CWE-306) within the E-Gate Atom 3X Projector (Model E04i32). The Android Debug Bridge (ADB) service is enabled and exposed over the network interface by default without any access control mechanisms. An attacker located on the same local network (adjacent) can connect to the device via ADB to execute shell commands with root privileges. This allows for complete compromise of the device's operating system, including data exfiltration and persistent unauthorized access. Users are advised to upgrade to the latest firmware version provided by the vendor.
Affected products
- E-Gate Atom 3X Projector (E04i32)
Timeline
- 2026-04-10: disclosed: Initial disclosure by CERT-In
- 2026-04-10: advisory