CVE-2022-38694 is an unchecked write-address vulnerability in the recovery-mode implementation of affected UNISOC BootROMs. Recovery commands processed through cmd_start and cmd_recv_data permit an attacker to control the destination address used for a write, creating an arbitrary-write primitive in the BootROM context. The missing destination-address validation can be used to corrupt security-critical memory during recovery-mode processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This 10-file repository is an operational Linux/bash wrapper and field guide for applying CVE-2022-38694 to the ZTE Blade V40 Vita P606F02 (Unisoc UMS9230 with UFS). It does not include the core CVE tooling or firmware binaries; those must be fetched or built separately from the referenced TomKing062 project. The primary entry point, scripts/unlock.sh, implements a six-stage process: back up and erase SPL, locally prepare images, install a temporary U-Boot-side payload, trigger the BootROM fallback-download unlock, inspect the unlock token in miscdata, and restore SPL/U-Boot. scripts/fix-post-unlock-hang.sh repeatedly waits for BROM and erases userdata plus metadata to address FBE key blobs sealed to the former locked state. verify-unlock.sh checks Android boot properties through adb, while watch-usb.sh polls Linux USB sysfs for device-state transitions. Supporting documentation supplies a UFS partition map, operating cautions, and troubleshooting notes. The workflow requires physical USB/BROM access and performs high-risk destructive partition operations; it has no network exploitation or command-and-control behavior.
This is a device-specific, operational bootloader-unlock repository for the Vankyo MatrixPad S30 (Unisoc SC9863A), not a network-facing exploit. Its top-level entry point, unlock.sh, provides an interactive five-phase USB download-mode workflow, while verify.sh reads miscdata to check the resulting unlock state. The intended S30 route does not normally need the CVE-2022-38694 ROP exploit because its BootROM is documented as accepting an unsigned FDL1 directly. Nevertheless, the repository vendors source and SoC stack-layout data for the CVE-2022-38694 technique, including an SC9863A payload targeting stack address 0x4ee8 for BootROM code execution on locked variants. The source/ directory contains build orchestration, PAC firmware extraction, device-file generation, U-Boot patching, diagnostics, partition reading, and Ghidra analysis scripts. The vendored CVE source supplies C utilities that trim DHTB-wrapped images, patch FDL1 verification paths, and NOP SPL signature-check sequences. A vendored spreadtrum_flash/spd_dump implementation communicates over libusb or Windows serial drivers and supports broad flash-management operations, including partition reads/writes/erase and reset. The primary patch_uboot.py produces two altered U-Boot/FDL2 images: one redirects boot flow to set_lock_status(1), persisting an unlock record, and another disables the secure-partition write check. The workflow first backs up and erases SPL, uses the patched cboot image to write unlock state, optionally sends a patched SPL, verifies miscdata, then restores the original SPL/U-Boot and wipes misc boot directives. Docs provide substantial reverse-engineering material on DHTB and SIMGHDR formats, the BootROM/SPL chain of trust, AVB behavior, and experimental follow-on work. exploit-artifacts/ contains hard-coded experimental Python patches to accept arbitrary AVB keys, bypass AVB checks, allow secure-partition writes, or divert FDL2 into a RAM boot path. These experiments use developer-specific absolute host paths and are ancillary rather than the primary unlock entry point. The exploit requires physical possession and a USB connection; it does not contact a C2 server, perform remote exploitation, or include a conventional shell payload.
Repository is a macOS port of a UNISOC/Spreadtrum BootROM/FDL flashing and dumping tool with an implemented CVE-2022-38694 exploit path. The core exploit lives in src/spd_dump.c, supported by protocol constants in src/spd_cmd.h and a simple Makefile. The exploit capability is not remote network exploitation; it is a physical USB attack against devices placed into BootROM download mode. The main technique is an out-of-bounds MIDST_DATA gap write ('exec_addr2') that abuses unchecked BootROM download writes to place a crafted blob at a chosen stack/return address, bypassing signature verification and allowing unsigned FDL1/FDL2 execution. Repository structure: src/ contains the patched C implementation of spd_dump; scripts/ contains operational helpers for building on macOS, generating backup/read commands from GPT XML, generating flash/write/erase command sequences, edge-triggered BootROM automation using pyusb, and a separate ttyd WebSocket client for interacting with headless web terminals. docs/ contains detailed protocol notes, exploit semantics for exec_addr2/CVE-2022-38694, partition handling rules, and a Magisk headless su authorization note. Operationally, the toolchain supports: detecting the BootROM USB device (1782:4d00), loading FDL1 and FDL2 at SoC-specific SRAM addresses, dumping the partition table, reading partitions to files, writing partitions from image files, erasing selected partitions including userdata, resetting/powering off the device, and patching vbmeta-family images by setting AVB flags to disable verification. The helper scripts encode community-derived partition safety rules, such as skipping or redirecting problematic NV/fixnv/calinv/runtimenv partitions. Notable endpoints are mostly local/physical artifacts: USB VID:PID 1782:4d00, image filenames such as fdl1-dl.bin/fdl2-dl.bin, GPT XML and generated operation files, Android filesystem paths for Magisk and block devices, and a localhost ttyd service at 127.0.0.1:1146 used by an auxiliary client. Overall, this is a real exploit-enabled flashing toolkit rather than a detector or README-only PoC.
This repository is a real exploit-oriented embedded flasher for CVE-2022-38694 targeting Unisoc/Spreadtrum BootROM download mode devices, especially documented around UDX710. It is not a generic PC exploit or a detection script; instead, it ports the exploitation workflow onto a Raspberry Pi RP2040/RP2350 microcontroller acting as a USB host. The main code lives in main.c and spd_protocol.c/.h. main.c initializes TinyUSB host mode, waits for a USB device with VID/PID 0x1782:0x4D00, opens raw bulk endpoints 0x81/0x01, and drives a loop for repeated automated flashing sessions. spd_protocol.c implements the Spreadtrum/Unisoc BSL protocol over raw USB bulk transfers, including HDLC framing, checksum/CRC handling, retries, timeouts, and a state machine covering BootROM handshake, payload upload, exec stub upload, and second-stage handshake. custom_exec_data.h embeds a 136-byte exec stub loaded at 0x3F28, explicitly described as bypassing BootROM signature verification. fdl1_data.h is only a placeholder and contains no real payload in this archive, meaning the repository ships the exploit framework/transport logic but expects the operator to provide a device-specific patched SPL/FDL blob for 0x28007000. The README and tutorial explain a two-stage process: an initial PC-assisted unlock using spd_dump and patched boot components, followed by hardened autonomous operation where the RP2350 repeatedly exploits devices that have been prepared to enter BootROM download mode on every boot. Overall capability: automated USB-host delivery of a signature-bypass exec stub and patched bootloader payload to vulnerable Unisoc devices, enabling arbitrary modified boot chain execution with minimal operator interaction.
This repository is a small operational proof-of-concept for CVE-2022-38694 targeting ZTE Android devices built on Unisoc chipsets. It is not a remote exploit framework; instead, it automates a USB/physical-access data extraction workflow. The repository contains two functional files: diagdump_poc.bat, which orchestrates the attack, and processor.py, which parses the dumped data. The two README files provide setup guidance and describe the extracted artifacts. The batch script is the main entry point. It first attempts to reboot a connected device into Unisoc autodloader/BROM mode using ADB, then invokes an external Unisoc utility (spd_dump.exe) with two FDL binaries to communicate with the boot ROM and read the ztepersist partition. After the dump completes, it runs processor.py against unisoc_brom\ztepersist.bin and writes a parsed report to zte_dump.txt. The Python parser does not exploit the device itself; it post-processes the dumped partition contents. It decodes the binary as ASCII with ignored errors, scans for structured strings, and extracts several categories of sensitive telemetry: app usage records keyed by RecordTime->, battery charging cycle records beginning with Begin:20 and containing ChargType:, OTA/firmware history lines containing Fingerprint ->, power/thermal counters matching POWERON_/POWEROFF_ patterns, and system health/event counters such as SYSTEM_* values, system_app_anr, and event_log. It then produces a consolidated report listing inferred installed apps with last-used dates, the last 100 app-use events, OTA history, system counters, power/thermal timers, and charging-cycle history. Overall, the exploit capability is unauthorized forensic-style extraction of persistent diagnostic/user telemetry from vulnerable ZTE Unisoc devices via boot ROM access. There are no hardcoded network C2 endpoints or exfiltration servers in the code; the notable observables are local file paths, the ADB/BROM commands, and the external GitHub release URL for required tooling.
This repository is a device-specific operational toolkit for Realme C53 (RMX3760) bootloader unlocking and rooting, centered on CVE-2022-38694 against the Unisoc/Spreadtrum boot chain. It is not a generic exploit framework module; instead it combines documentation, shell scripts, a Python CLI wrapper, partition notes, and vendor unlock artifacts. The main exploit capability is in scripts/unlock.sh and mirrored in cli.py cmd_unlock(), which use spd_dump.exe to dump PGPT/SPL/U-Boot, generate a patched SPL with gen_spl-unlock.exe, temporarily replace boot-chain components, write the spl-unlock.bin payload, then restore original bootloader components and wipe misc-related state to leave the bootloader unlocked. The workflow requires physical USB access and manual device interaction ('screwdriver step' / button sequence) to enter SPRD U2S Diag mode. After unlock, the repository provides two persistent root paths. scripts/root_magisk.sh and cli.py cmd_root() extract binaries from Magisk-v30.7.apk, push them to /data/local/tmp/magisk on the phone, patch a dumped stock boot image with boot_patch.sh, and flash the resulting image to both boot_a and boot_b via fastboot. scripts/root_kernelsu.sh offers a more advanced KernelSU LKM path: it fetches KernelSU setup.sh from raw.githubusercontent.com, builds kernelsu.ko from local kernel source, downloads ksud from GitHub releases, patches the boot image on-device, and flashes both slots. scripts/backup.sh and cli.py cmd_backup()/cmd_dump_boot() support pre-unlock media backup and stock boot extraction from /dev/block/by-name/boot_a. cli.py wraps the full process in an interactive menu and includes root verification via adb shell su -c id. Repository structure: README.md and README.id.md are detailed English/Indonesian guides; AGENTS.md is an AI-oriented operational note file; scripts/ contains the main automation; tools/unlock/ contains configuration and binary payload support files for the Unisoc unlock chain; files/partition_layout.txt documents the target partition map and highlights miscdata as the unlock flag location. The included batch file tools/unlock/unlock_autopatch_9230.bat appears to be an alternate Windows-native automation path for the same exploit chain. Overall, this is a real, device-targeted exploit-and-rooting repository with operational post-exploitation capability rather than a mere detector or documentation-only PoC.
This repository is a Windows batch-script toolkit for rooting supported Unisoc UMS9230/T615 Android devices, especially the ATOZEE P12 on Android 14, by combining an external bootloader-unlock exploit chain for CVE-2022-38694 with a Magisk boot-image patch/flash workflow. It is not a standalone exploit implementation of the CVE itself; instead, it operationalizes publicly available external unlock tooling and wraps the full process in guided scripts. Repository structure is small and straightforward: documentation files (README, DOWNLOADS, TROUBLESHOOTING, DEVICES, CHANGELOG, CONTRIBUTING), three batch scripts (`p12_autoroot.bat`, `p12_root.bat`, `scripts/verify_env.bat`), and placeholder directories for firmware, Magisk artifacts, and external unlock binaries. The actual exploit binaries and loader files are intentionally excluded via `.gitignore` and must be downloaded separately. Main capabilities: - `p12_autoroot.bat`: primary orchestrator for the rooting pipeline. It performs preflight checks, validates adb/fastboot presence, checks for external unlock tooling and Magisk APK, detects the connected device, invokes the external `unlock_autopatch_9230.bat` workflow for bootloader unlocking, then guides/automates later phases for boot patching, flashing, and root verification. It logs activity to `C:\P12\autoroot_log.txt` and assumes a fixed directory layout under `C:\P12`. - `p12_root.bat`: post-root utility toolkit. Based on the visible sections and README, it supports device connection checks, debloating packages, APK installation, file push/pull, reboot actions, and root verification using `su` and `magisk -v`. It logs to `p12_root_log.txt`. - `scripts/verify_env.bat`: environment validator that checks for adb, fastboot, optional git, required folder structure, required external unlock files (`spd_dump.exe`, `fdl1-dl.bin`, `fdl2-dl.bin`, `fdl2-cboot.bin`, `unlock_autopatch_9230.bat`), Magisk APK presence, optional patched image presence, and whether the connected device reports `ums9230`. Attack model: this is a local/physical USB-assisted rooting workflow, not a remote network exploit. The operator must have physical access to the device, connect it over USB to a Windows machine, enable USB debugging for adb phases, and manually place the device into the required mode for the Unisoc unlock stage. The exploit target is the device bootloader path exposed by CVE-2022-38694, after which the scripts use standard adb/fastboot operations to install Magisk-based root. Notable fingerprintable artifacts include hardcoded Windows paths under `C:\P12`, on-device path `/sdcard/Download/`, expected external binaries in `unlock\unlocker`, and download URLs for the external unlock tool, drivers, platform tools, Magisk, and Shamiko. The repository also references the Android package `com.guanhong.guanhongpcb` as a debloat target. Overall, this is a practical operational wrapper around an external Unisoc bootloader-unlock exploit plus Magisk rooting steps. Because it includes payload-bearing automation and post-exploitation/root-management functionality, but relies on hardcoded paths and external tools, its maturity is best classified as OPERATIONAL rather than a generic framework or a simple PoC.
Repository purpose: a Linux-based toolset and step-by-step guide to unlock the bootloader of the Itel S23 (S665L) on Unisoc T606/UMS9230 by leveraging CVE-2022-38694 (Unisoc BootROM signature verification bypass). The exploit concept is to use a small binary payload (custom_exec_no_verify_*) to overwrite/patch a BootROM verification function pointer at a fixed memory address (notably 0x65015f08; alternate 0x65015f48), causing the BootROM to accept unsigned FDL loaders. Once unsigned code execution in the BootROM download flow is achieved, the tooling performs raw partition operations to flash a modified uboot (fdl2-cboot.bin) and send a generated unlock payload (spl-unlock.bin), then verifies unlock by reading miscdata and finally restores original boot components. Repository structure (9 files): - Top-level docs: README.md and CLAUDE.md provide device-specific parameters (addresses, offsets, modes) and a procedural unlock workflow. - Core automation: tools/spreadtrum_flash_linux/unlock.sh is the main entry point for the Itel S23 flow, orchestrating spd_dump and gen_spl-unlock across 6 steps (erase/backup, generate payload, flash modified uboot, send unlock payload, verify via miscdata read, restore splloader/uboot). - Additional tooling: tools/spreadtrum_flash_linux/menu.sh is an interactive multi-SoC menu (UMS9230/SC9863A/UMS512) that builds spd_dump command lines using per-SoC addresses and offers actions beyond unlocking (wipe misc via misc-wipe.bin, disable verity, switch A/B slot, reboot to recovery/fastboot, poweroff, and a persist partition read/erase sequence labeled FRP reset). - Firmware extraction helper: tools/spreadtrum_flash_linux/extrac.sh is a PAC archive extraction menu that executes local pacextractor/unpac utilities (not included in this repo listing) and writes outputs to an extract/ directory. - Binary artifacts: misc-wipe.bin and misc-fastbootd.bin are small misc-partition payloads containing boot-recovery directives (e.g., --wipe_data, --fastboot). tools/ums9230.txt is a command cheat-sheet with the key spd_dump invocations. Exploit capabilities (actionable): - BootROM-level signature verification bypass (CVE-2022-38694) via exec_addr patching at hardcoded addresses. - Upload and execute FDL stages (fdl1/fdl2) at specified RAM addresses. - Read/erase/write critical partitions (splloader, uboot, miscdata, persist, misc) enabling bootloader unlock, device wipe triggers, and other maintenance/abuse operations. No network C2 or remote endpoints are present; the attack vector is local/physical over USB in BootROM/BROM mode with privileged host access.
Repository purpose: a Linux-based toolset and step-by-step guide to unlock the bootloader of the Itel S23 (S665L) on Unisoc T606/UMS9230 by leveraging CVE-2022-38694 (Unisoc BootROM signature verification bypass). The exploit concept is to use a small binary payload (custom_exec_no_verify) to overwrite/patch the BootROM verification function pointer at a fixed RAM address (documented as 0x65015f08, with an alternate 0x65015f48), allowing unsigned FDL download agents to be accepted. Core capabilities (as implemented by scripts/docs): - BootROM exploitation over USB (BROM mode) using spd_dump with exec_addr to apply the no-verify patch. - Raw flash operations via spd_dump once FDLs are loaded: read (backup) partitions (splloader, uboot), erase partitions (splloader, splloader_bak), write partitions (uboot, splloader), and read miscdata to verify unlock state. - Generation and delivery of an unlock payload: gen_spl-unlock creates spl-unlock.bin from splloader.bin using a firmware-specific offset (0xfd28 in this repo’s documentation), then spd_dump loads it as an FDL to trigger the unlock. - Additional device-management actions exposed in menu.sh: wipe data by writing misc-wipe.bin to misc, boot/reboot modes, disable verity, FRP reset by erasing persist, and A/B slot switching. Repository structure: - Top-level documentation: README.md and CLAUDE.md describe device specifics, required addresses, prerequisites (udev rules, sudo), and the full 6-step unlock flow. - tools/spreadtrum_flash_linux/: operational scripts and binary artifacts. - unlock.sh: the main automation entry point orchestrating the 6-step process (backup/erase, generate payload, flash modified uboot, send unlock payload, verify via miscdata read, restore originals). - menu.sh: an interactive Bash menu for multiple Unisoc SoCs (UMS9230/SC9863A/UMS512) that builds spd_dump command lines using SoC-specific addresses and can perform unlock-adjacent operations. - extrac.sh: helper script to unpack .pac firmware archives using external tools (pacextractor/unpac). - misc-wipe.bin and misc-fastbootd.bin: misc partition command payloads containing recovery boot arguments (--wipe_data / --fastboot). - tools/ums9230.txt: a concise command cheat-sheet for the UMS9230 flow. Notable targeting details: - Explicitly targets Itel S23 S665L (Android 12) with Unisoc T606 (UMS9230). Addresses and SPL offset are device/firmware-specific and hardcoded in docs/scripts. - Attack is not network-based; it requires physical USB access and BootROM mode interaction.
This repository is a Windows Forms (.NET Framework 4.7.2) GUI application named "UnisocUNLOCKER" that operationalizes an FRP-bypass workflow based on CVE-2022-38694 for Unisoc/Spreadtrum devices in EDL mode. It is not a network exploit; it is a local/physical attack tool that depends on USB connectivity, EDL mode, and external device-specific packages. Core behavior (Form1.cs): the UI lets the user select a device model/CPU from a large hardcoded catalog (DeviceInfo.cs). When the user confirms "FRP UNLOCK" and then presses the 'Z' key, StartFRPUnlock() locates a per-device directory under Devices\\<Folder>, finds an *unlock*.bat file, parses it for a line beginning with 'spd_dump' containing 'exec', and constructs a modified command that forces the exec sequence to "exec r persist e persist reset". It then launches the extracted executable (typically spd_dump) with those arguments via Process.Start, aiming to erase/reset the Android persist partition (commonly used to store FRP state). Driver helper: the "INSTALL SPD DRIVER" button attempts to run a bundled driver installer at Driver\\Win10/Win8/Win7\\DriverSetup.exe depending on OS version. Repository structure: Program.cs is the WinForms entry point; Form1.* implements the UI and execution logic; DeviceInfo.cs contains the device database mapping models/SoCs to folder names; the remaining files are standard Visual Studio project metadata/resources/manifests. The actual low-level exploit tooling (spd_dump, bat scripts, device zips) is intentionally external and must be downloaded from the referenced CVE-2022-38694 unlock_bootloader release and placed into the expected Devices directory layout.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.