CVE-2020-27402: Hindotech HK1 Box s905x3 Firmware

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb.

Affected products

  • Hindotech HK1 Box s905x3 Firmware: version hk1_x3_s905x3_4bit_v11_2019-11-05 only

Published 2020-11-05. Last modified 2026-06-17.