External risk intelligence

HiDPT Android Debug Bridge Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-78745

The vulnerability involves the Android Debug Bridge (ADB) daemon. While network-reachable, ADB is typically intended for developer use, debugging, or local administration, and it is standard practice to disable it or restrict access behind internal network controls rather than exposing it directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects devices running specific HiDPT Android software, allowing remote code execution through the Android Debug Bridge. The main concern is confirming relevance and exposure, as the Android Debug Bridge is typically used for development and debugging and not intended for direct public internet exposure.

  • Remote code execution risk via ADB.
  • Confirm relevance and exposure.
  • Understand potential device compromise.

Attack Path

How an attacker could exploit the issue

An attacker could initiate a network connection to a device running the vulnerable software. This connection targets the Android Debug Bridge daemon, which lacks proper access controls. Successful interaction with this daemon could allow the attacker to execute arbitrary code on the device.

  • Network access to the device is required.
  • Attacker interacts with the ADB daemon.
  • Arbitrary code execution is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a remote attacker to execute arbitrary code on affected systems. This may occur when the Android Debug Bridge (ADB) daemon is accessible over the network, potentially enabling unauthorized actions.

  • Arbitrary code execution.
  • Network access to ADB daemon.
  • System compromise and data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Android Debug Bridge (ADB) daemon affects devices running HiDPT/Weyon HiDPTAndroid Hi3751V350 and Hi3751V352E_DMO. The primary responsibility for addressing this likely falls to platform or device owners, who must first identify all instances of the affected technology, determine their network reachability and business criticality, and then work with relevant teams to plan remediation.

  • Platform or device owners should manage this.
  • Verify ADB daemon network exposure and access.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the HiDPT Android software affected by CVE-2026-78745?

This software refers to the Android-based operating environment found on specific Weyon HiDPT hardware platforms, including the Hi3751V350 and Hi3751V352E_DMO chipsets. These platforms are typically integrated into smart displays or television systems, providing the core interface and application management capabilities that allow these devices to function as connected multimedia units.

How does CVE-2026-78745 allow unauthorized code execution?

This vulnerability is classified as an Improper Access Control issue (CWE-284). It specifically affects the Android Debug Bridge (ADB) daemon, a service designed to help developers manage devices. Because the daemon lacks sufficient security checks, an attacker who establishes a network connection can bypass intended restrictions and force the system to run arbitrary commands, granting them control over the device.

Do I need to be on the same local network for this to trigger?

No, being on the same local network is not a requirement for this vulnerability. The flaw exists because the ADB daemon is accessible via network connections. While it does not trigger if the service is completely disabled or strictly firewalled, it can be reached by any attacker capable of establishing a network path to the vulnerable daemon, even from outside the immediate local area.

How do I know if my device is at risk?

According to Halo Surface Signal, risk depends on whether the ADB service is reachable. While ADB is a powerful tool for debugging, it is rarely intended for public internet access. You are at higher risk if your device is configured such that its management ports are visible to the internet rather than restricted to trusted internal networks or disabled entirely.

What should I do if I am running this technology?

First, conduct an inventory to locate all HiDPT-based devices in your environment. Next, verify if the ADB daemon is running and determine if it is exposed to the network. If the service is active and accessible, prioritize restricting network access immediately to prevent unauthorized connections while you coordinate with your device supplier or platform administrator for official security updates.

References