CVE-2020-27402
Summary
| CVE | CVE-2020-27402 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-05 15:15:00 UTC |
| Updated | 2021-06-17 18:01:00 UTC |
| Description | The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hidotech | Hk1 Box S905x3 | - | All | All | All |
| Hardware | Hidotech | Hk1 Box S905x3 | - | All | All | All |
| Operating System | Hidotech | Hk1 Box S905x3 Firmware | hk1_x3_s905x3_4bit_v11_2019-11-05 | All | All | All |
| Operating System | Hidotech | Hk1 Box S905x3 Firmware | hk1_x3_s905x3_4bit_v11_2019-11-05 | All | All | All |
| Hardware | Hindotech | Hk1 Box S905x3 | - | All | All | All |
| Operating System | Hindotech | Hk1 Box S905x3 Firmware | hk1_x3_s905x3_4bit_v11_2019-11-05 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Уязвимость в приставках Hindotech HK1 TV Box позволяет похищать пароли и переписку | MISC | www.securitylab.ru | Third Party Advisory |
| security/SICK-2020-004.md at master · sickcodes/security · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| Privilege escalation in Hindotech HK1 Box S905X3 TV Box | MISC | www.cybersecurity-help.cz | Third Party Advisory |
| SICK-2020-004 - Hindotech HK1 TV Box - Root Privilege Escalation - Improper Access Control - Sick Codes - Linux, NetSec, VPS, Arch, Debian, CentOS Tweaks & Tips! | MISC | sick.codes | Exploit, Third Party Advisory |
| Authentication Bug Opens Android Smart-TV Box to Data Theft | Threatpost | MISC | threatpost.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.