Allwinner designs system-on-chip processors and firmware widely embedded in consumer electronics and development boards such as the A64, A83T, and H3 variants, with vulnerability exposure centered on their Linux-based bootloaders and kernel implementations. The durable signal across disclosures focuses on information-disclosure weaknesses that arise from improper data handling in low-level firmware and kernel code, a pattern typical of embedded systems where memory layout and sensitive register contents may be exposed to insufficiently privileged actors. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Allwinner over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10225HIGH The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice" to /proc/sunxi_debug/sunxi_de | Mar 27, 2017 | 7.8 | 37 | NO | YES |
CVE-2017-5927HIGH Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel at | Feb 27, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-5926HIGH Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel at | Feb 27, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-5925HIGH Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel | Feb 27, 2017 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Allwinner.
Media articles that mention a CVE ID that affects a product developed by Allwinner — matched by CVE ID, not by vendor name.