
CVE-2024-36842, Creating Persistent Backdoor on Oncord+ android/ios car infotaiment using malicious script!
# CVE-2024-36842 Backdooring-Oncord+ Android-Sterio We have conducted vulnerablity assessment on one of the most selling after marrket car infotainment unit. Creating Persistent Backdoor on Oncord+ android/ios car infotainment unit using malicious script!
About Device: **Android version : 12
Kernel Version : 4.9.170
Model : TS17/Powered by Allwinner
Serial number : 0x03125dBa
**






Android sterio unit by Oncord+ provides excellent performance and maintenance system based on cutting-edge technology. It is most available after market android unit fro cars in India and other countries.

** _Vulnerability ID Vulnerability Severity CVSS Score
NW-VUL-01 Gaining Root access of the Infotainment Unit by exploiting ADB port HIGH - 8.4
HW-VUL-02 Gaining Root access through UART Port – Improper Access Control MEDIUM - 6.4_ **