CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability
Vulnerability
A local privilege escalation vulnerability has been identified in CarlinKit CPC200-CCPA devices. This issue arises from a misconfiguration in the application system-on-chip (SoC), specifically the absence of a properly established hardware root of trust. As a result, local attackers who can execute low-privileged code may exploit this vulnerability to escalate privileges and run arbitrary code during the boot process.
Impact
Exploitation of this vulnerability allows local attackers to escalate privileges and execute arbitrary code in the context of the boot process.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
3.3remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
0.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
