In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution privileges needed.
Loading...
Loading...
Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2025-09-02. NVD baseline CVSS 7.8; sources differ by 0.0.
In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution privileges needed.
September 1, 2025
April 15, 2026
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (5 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.
Open source ↗rooting an ATOZEE P12 on Android 14 using CVE-2022-38694 — because fastboot oem unlock said no, so we found another way.
Open source ↗Bootloader unlock using CVE-2022-38694 for Retroid Pocket 3+
Open source ↗Bootloader unlock using CVE-2022-38694 for Anbernic Unisoc T820 devices
Open source ↗This is a one-time signature verification bypass. For persistent signature verification bypass, check https://github.com/TomKing062/CVE-2022-38691_38692
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-38694
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
CWE-250