CVE Explorer
CVE-2026-5777
This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading to complete compromise of the targeted device.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Atom 3X Projector","vendor":"EGate","versions":[{"lessThan":"Mar Tue 10 17:57:35 CST 2026","status":"affected","version":"Wed Jun 18 10:35:47 CST 2025","versionType":"date"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a2b9af723c729f5dcf8c3a66149d03a53371401af35eb0c6fa8246e4874bc930 · sha256:5484e993c6937dbe… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a2b9af723c729f5dcf8c3a66149d03a53371401af35eb0c6fa8246e4874bc930 · sha256:5484e993c6937dbe… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306 Missing authentication for critical function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a2b9af723c729f5dcf8c3a66149d03a53371401af35eb0c6fa8246e4874bc930 · sha256:5484e993c6937dbe… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["third-party-advisory"],"url":"https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0179"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a2b9af723c729f5dcf8c3a66149d03a53371401af35eb0c6fa8246e4874bc930 · sha256:5484e993c6937dbe… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.