# Kernel exploit to root sonim?

**URL:** <https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180>\
**Category:** Sonim Phones\
**Tags:** linux, root, sonim-xp3-series, exploit, question\
**Created:** [December 7, 2025, 5:53am UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180 "2025-12-07T05:53:06Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [December 7, 2025, 1:39pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/21 "2025-12-07T13:39:36Z")

</div>

@leobuskin is your man, he did all the work already. Don’t think he’s available now though. Might want to read through his posts here.

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [December 7, 2025, 2:02pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/22 "2025-12-07T14:02:23Z")

</div>

Just checked out those stuff. When i was reading up on my vulnerability i did see other vulnerabilities but that guy wow he knows his stuff. I don’t have any kyocera to work with and anyway i’m not a fan of that phone. Still curious what that file is. It sounds like a file within the rom

#offtopic

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [December 7, 2025, 2:04pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/23 "2025-12-07T14:04:35Z")

</div>

> [@flipphoneguy](#):
>
> Still curious what that file is.

What?

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [December 7, 2025, 2:30pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/24 "2025-12-07T14:30:33Z")

</div>

in the kyocera thread. The aboot eng file you weren’t supposed to have. Does that mean a secondary aboot file signed but not meant for production?

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [December 7, 2025, 2:40pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/25 "2025-12-07T14:40:38Z")

</div>

Yes

---

<div class="post-metadata">

**Author:** ![ys770](https://jtechforums.org/user_avatar/jtechforums.org/ys770/32/2595_2.png) [@ys770](https://jtechforums.org/u/ys770)\
**Post date:** [December 7, 2025, 8:49pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/26 "2025-12-07T20:49:50Z")

</div>

if this works on the xp3800 i have a few you can play with

---

<div class="post-metadata">

**Author:** ![ars18](https://jtechforums.org/user_avatar/jtechforums.org/ars18/32/11805_2.png) [@ars18](https://jtechforums.org/u/ars18)\
**Post date:** [December 7, 2025, 8:56pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/27 "2025-12-07T20:56:20Z")

</div>

I have too much to do 😭

---

<div class="post-metadata">

**Author:** ![Dev-in-the-BM\_2.0](https://jtechforums.org/user_avatar/jtechforums.org/dev-in-the-bm_2.0/32/969_2.png) [@Dev-in-the-BM\_2.0](https://jtechforums.org/u/Dev-in-the-BM_2.0)\
**Post date:** [December 7, 2025, 9:40pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/28 "2025-12-07T21:40:00Z")

</div>

> [@ars18](#):
>
> You will have a collection of bricked ones like I have the e4810s lol

Playing with Xp3800’s should be a lot cheaper than tinkering with Kyocera’s.

You can get locked Xp3800’s for ~$40.

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [December 7, 2025, 10:00pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/29 "2025-12-07T22:00:49Z")

</div>

true. And sprint 2nd hand on ebay for about 10 since it can’t be unlocked.  
I have to first see the kernel version on the xp3. I have 1 but can’t find it right now. If someone can check in settings about the kernel version and post it here…

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [December 7, 2025, 11:49pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/30 "2025-12-07T23:49:59Z")

</div>

Just tried compiling for xp3 and realized that xp3 is 32 bit and since the script is touching raw bits and addresses it can’t just be compiled for other architectures. The entire script has to be fixed up for it. Beyond my paygrade obviously.

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [December 16, 2025, 5:35am UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/31 "2025-12-16T05:35:18Z")

</div>

Is anyone actually interested in a root app mini magisk style for the sonim xp5800.specifically or will it be like the other stuff i made for sonim which only i myself used…?  
(not planning on keeping this specific sonim for more then another half year or so, so if no1s interested why bother)

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [February 6, 2026, 7:38am UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/32 "2026-02-06T07:38:40Z")

</div>

persistent global root (available also for other apps) coming soon…

(xp5800 only meanwhile)

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [February 6, 2026, 12:55pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/33 "2026-02-06T12:55:25Z")

</div>

> [@Root sonim xp5800 solution](https://jtechforums.org/t/root-sonim-xp5800-solution/5822):
>
> After much work and giving up i finally got back to it. Put together full root. It’s now persistent and accessible root access for any app!! Tested and it works perfectly! [https://github.com/flipphoneguy/root\_sonim\_xp5s](https://github.com/flipphoneguy/root_sonim_xp5s) a lot of info in README play_button README enjoy! Please keep this topic clean. Comments are welcomed and appreciated: [https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180)

please provide feedback!

---

<div class="post-metadata">

**Author:** ![jumptoheaven](https://jtechforums.org/user_avatar/jtechforums.org/jumptoheaven/32/5700_2.png) [@jumptoheaven](https://jtechforums.org/u/jumptoheaven)\
**Post date:** [February 6, 2026, 1:40pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/34 "2026-02-06T13:40:16Z")

</div>

I personally don’t have a Sonim, but it seems very impressive!

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [February 6, 2026, 1:57pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/35 "2026-02-06T13:57:49Z")

</div>

Thanks!!

---

<div class="post-metadata">

**Author:** ![TripleU](https://jtechforums.org/user_avatar/jtechforums.org/tripleu/32/488_2.png) [@TripleU](https://jtechforums.org/u/TripleU)\
**Post date:** [February 6, 2026, 2:35pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/36 "2026-02-06T14:35:54Z")

</div>

Would love to exploit every known cve exploit on the Kyocera’s and LG’s.

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [February 6, 2026, 2:59pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/37 "2026-02-06T14:59:54Z")

</div>

If i’d have 1 i’d look into it. I love cve’s

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [February 7, 2026, 11:18pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/38 "2026-02-07T23:18:07Z")

</div>

typical developers nightmare. Exact same (literally identical) devices, same update date, exact same kernel version and everything, exact same environment… on 2 devices i tested it it worked. On the third it failed. Can’t figure out how in the world this is possible. It’s failing to find the selinux rules. I’ll update soon if i can fix it. If anyone tests it let me know if it works by you.

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [February 8, 2026, 8:48am UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/39 "2026-02-08T08:48:56Z")

</div>

Besides fixing that bug and some others, its much more stable and easier to manage and with new features. i also worked for hours rewriting parts to be more robustly compatible for this specific phone. Same link same repo just updated. Check it out:

> **[GitHub - flipphoneguy/root\_sonim\_xp5s: full persistent root solution for the Sonim xp5800](https://github.com/flipphoneguy/root_sonim_xp5s)**
>
> full persistent root solution for the Sonim xp5800

---

<div class="post-metadata">

**Author:** ![flipphoneguy](https://jtechforums.org/user_avatar/jtechforums.org/flipphoneguy/32/11165_2.png) [@flipphoneguy](https://jtechforums.org/u/flipphoneguy)\
**Post date:** [February 8, 2026, 1:25pm UTC](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180/40 "2026-02-08T13:25:30Z")

</div>

App coming soon…

i realized i can just take together the files i already have and just have an app execute them.

[Previous page](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180.md?page=1)

[Next page](https://jtechforums.org/t/kernel-exploit-to-root-sonim/5180.md?page=3)
