National Cyber Warfare Foundation (NCWF)


0 user ratings
2025-10-08 18:59:21
sshively

 - archive -- 
Super Box Case

The XH9810 is a Bluetooth chip developed by XIHAO Intelligent Technology Co., Ltd.. 

It is certified as a generic "Bluetooth chip," meaning it is a core component that can be used in various products. 
Unlike a consumer-facing product like a smartphone, the XH9810 does not have different "models" for sale to the public. Instead, it is an integrated circuit intended for use by original equipment manufacturers (OEMs) and developers to build their own end products. It is the core component that provides Bluetooth connectivity to those devices. 

Other chips in the XIHAO XH98XX series include:


XIHAO Bluetooth chip, XH9810~ 
XIHAO Bluetooth chip, XH9800~ XIHAO 
Bluetooth chip, XH9820~ XIHAO
Bluetooth chip, XH9830~ XIHAO
Bluetooth chip, XH9840~ XIHAO
Bluetooth chip, XH9850~ XIHAO
Bluetooth chip, XH9860~ XIHAO 
Bluetooth chip, XH9870~ XIHAO 
Bluetooth chip, XH9880~ XIHAO
Bluetooth chip, XH9890~ XIHAO 
Bluetooth chip, XH9801~ XIHAO 
Bluetooth chip, XH9802~ XIHAO 
Bluetooth chip, XH9803~ XIHAO
Bluetooth chip, XH9804~ XIHAO 
Bluetooth chip, XH9805~ XIHAO 
Bluetooth chip, XH9806~ XIHAO 
Bluetooth chip, XH9807~ XIHAO 
Bluetooth chip, XH9808~ XIHAO 
Bluetooth chip, XH9809~ XIHAO 
Bluetooth chip, XH9701-B~ XIHAO
Bluetooth chip, XH9702-B~ XIHAO
Bluetooth chip, XH9703-B~ XIHAO 
Bluetooth chip, XH9704-B~ XIHAO
Bluetooth chip, XH9705~ XIHAO
Bluetooth chip, XH9705-B~ XIHAO
Bluetooth chip, XH9706-B~ XIHAO 
Bluetooth chip, XH9707-B~ XIHAO 
Bluetooth chip, XH9708-B~ XIHAO
Bluetooth chip, XH9709-B

Bluetooth vulnerabilities enable nearby attackers to exploit weaknesses in the wireless communication protocol, allowing them to compromise devices, including smart TVs.
Standard attack methods include: 

Botnet recruitment: In 2024, a warning was issued about malware that hijacks Android-based TV boxes, turning them into participants in a botnet. Some of these devices were pre-infected, while others were compromised during the setup process. The malware utilizes the device's internet connection to facilitate fraud and other cybercrimes. 

Bluejacking: Sending unsolicited messages, which can contain malicious links to distribute malware or phishing scams.

Bluebugging: Taking control of a device to make calls, send messages, or access data.

Bluesnarfing: Stealing data, such as contacts and emails, from a device.

BlueBorne: A collection of vulnerabilities that allows attackers to take complete control of a device via Bluetooth without user interaction and spread malware to other vulnerable devices.

Key Injection (CVE-2023-45866): A flaw that allows a threat actor to trick a Bluetooth device into pairing with a fake keyboard without user confirmation. On vulnerable smart TVs and Android devices, this can allow an attacker to inject keystrokes and execute arbitrary commands.

Access Control Flaw (CVE-2022-44636): A vulnerability in some Samsung TVs that allows a remote attacker to enable microphone access via Bluetooth spoofing. 



Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.