AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-6597

MEDIUM · CVSS 6.8 EPSS 0.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-08-29 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-6597
Severity
MEDIUM
CVSS
6.8
EPSS
0.50%
Linux

Original Filing — NVD Description

The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidden privilege escalation capability to achieve command execution as the root user. They have made modifications that allow a user with physical access to the device to obtain a root shell via ADB. Modifying the read-only properties by an app as the system user creates a UNIX domain socket named factory_test that will execute commands as the root user by processes that have privilege to access it (as per the SELinux rules that the vendor controls).