ZeroHour

CVE-2026-78745

large

Remote code execution via ADB daemon in Weyon/HiDPT Hi3751 set-top boxes

CVSS 3.1
9.8 critical
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-78745 is an improper access-control flaw (CWE-284) in the Android Debug Bridge daemon (adbd) of the HiDPTAndroid software stack for the Weyon/HiDPT Hi3751V350 and Hi3751V352E_DMO set-top-box platforms. A remote attacker who can reach the device's adbd service over the network can exploit the flaw to execute arbitrary code without credentials or user interaction, consistent with the 9.8 CVSS score (AV:N/AC:L/PR:N/UI:N). Affected products are Android TV set-top-box platforms built on the Hisilicon Hi3751V350 or Hi3751V352E_DMO silicon running the HiDPTAndroid build; the advisory data does not specify affected or fixed version ranges. Exploitation status is currently quiet: there is no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts 30-day exploitation probability at 0.7% (52nd percentile).

What to do: Restrict or disable ADB over the network (classically TCP port 5555) on affected set-top boxes and block inbound access to adbd at the network edge, since the flaw is network-reachable without authentication. Contact the vendor for patched firmware for the Hi3751V350 and Hi3751V352E_DMO platforms, as no fixed versions are listed in the available data. Audit deployed devices to determine whether adbd is listening on any network interface and whether those devices are reachable from the internet or shared operator networks.

Affected
HiDPT / Weyon HiDPTAndroid Hi3751V350
HiDPT / Weyon HiDPTAndroid Hi3751V352E_DMO
Estimated exposure
largeon the order of 100,000-1,000,000 deployed set-top boxes; exact counts and the internet-reachable subset unknown — Hi3751V350/V352E are Hisilicon set-top-box SoCs deployed in pay-TV/Android TV operator fleets that typically ship in the hundreds of thousands, but no published install or internet-exposure counts exist for the specific HiDPTAndroid/Weyon…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.