The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious apps can use the interface provided by the service to set the number of applications allowed to run in the background to 0 and add themselves to the whitelist, so that once other applications enter the background, they will be forcibly stopped by the system, causing a denial of service.
Conclusion & alert: CVE-2021-38788 is rated Moderate Risk (56.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.68%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.79% | 1.68% | +0.89% |
| 2 | 2025-03-30 | 0.94% | 0.79% | -0.15% |
| 3 | 2025-03-29 | — | 0.94% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| allwinnertech | android_q_sdk | 1.0 | cpe:2.3:a:allwinnertech:android_q_sdk:1.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/pokerfacett/MY_CVE_CREDIT/blob/master/Allwinner%20R818%20SoC%EF%BC%9Abackground%20service%20has%20EoP%20Vulnerability.md | Broken Link Third Party Advisory |
| https://vul.wangan.com/a/CNVD-2021-46928 | Third Party Advisory |
| https://www.allwinnertech.com/index.php?c=product&a=index&id=92 | Product Vendor Advisory |
| https://www.cnvd.org.cn/flaw/show/CNVD-2021-46928 | Third Party Advisory |