CVE-2018-10988: Diqee DIQEE360 Firmware
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, without a digital signature, as root from the /mnt/sdcard/$PRO_NAME/upgrade.sh or /sdcard/upgrage_360/upgrade.sh pathname.
Affected products
- Diqee DIQEE360 Firmware: affected versions not specified
Published 2018-07-05. Last modified 2026-06-17.