Junglewise Threat Intelligence

CVE-2026-58378: Allwinner H616 TV Box exposed ADB interface

CVE-2026-58378 · Severity: high · CVSS 8.8 · Published 2026-07-09

Executive brief

The Allwinner H616 TV Box TV98 contains a security flaw where debugging tools used during development were left active in the final consumer product. These tools are accessible over the network, allowing a remote attacker to request control of the device. If a user inadvertently approves this request, the attacker can gain full administrative control, potentially leading to the theft of personal data or the installation of malicious software.

Technical details

This vulnerability is classified as Active Debug Code (CWE-489). The Allwinner H616 TV Box TV98 production firmware leaves the Android Debug Bridge (ADB) enabled and listening on network interfaces. An unauthenticated attacker on the same network can initiate an ADB connection request. While the attack requires a minimal level of user interaction (the victim must accept the ADB authorization prompt appearing on the screen), successful exploitation grants the attacker root-level shell access to the device operating system. This allows for complete system compromise, including data exfiltration and persistent malware installation.

Affected products

  • Allwinner H616 TV Box TV98 All versions

Timeline

  • 2026-07-09: advisory: Initial NVD publication date

References