Junglewise Threat Intelligence

CVE-2026-78745: Weyon HiDPTAndroid remote code execution via exposed ADB daemon

CVE-2026-78745 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Executive brief

Weyon HiDPTAndroid smart televisions expose the Android Debug Bridge (ADB) service to remote networks without proper access controls. An attacker on the network can connect to this service and execute arbitrary code with root privileges, gaining complete control over the device. This could allow an attacker to compromise user data, disable the device, or use it as a foothold for further attacks on the home or corporate network.

Technical details

The vulnerability is a remote code execution issue caused by exposed and unauthenticated Android Debug Bridge (ADB) daemon on HiDPT/Weyon HiDPTAndroid devices. The ADB service is remotely accessible over the network without requiring authentication or encryption, and operates with root-level privileges. An attacker can establish an ADB session from any network-reachable location and execute arbitrary commands as root. The affected component is the Android Debug Bridge daemon (adbd) on the Hi3751V350 and Hi3751V352E_DMO platforms. No vendor patch is currently available; mitigation requires disabling ADB or restricting network access to the service.

Affected products

  • Weyon HiDPTAndroid Hi3751V350, Hi3751V352E_DMO

Timeline

  • 2026-05-26: disclosed: Vulnerability discovered by researcher
  • 2026-05-26: disclosed: Reported to vendor (no response received)
  • 2026-06-08: other: Vulnerability submitted to MITRE for CVE assignment
  • 2026-09-02: disclosed: CVE-2026-78745 assigned by MITRE
  • 2026-09-03: disclosed: Public disclosure

References