In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution privileges needed.
https://github.com/redzrush101/zte-blade-v40-vita-unlock
https://github.com/Gadorach/vankyo-s30-bootloader-unlock
https://github.com/xun404/spd_dump-macos
https://github.com/mutur4/UnisocBootROMs
https://github.com/sloden1977-lang/ROOT-ZTE-X1001
https://github.com/Gopartner/realme-c53-unlock-root
https://github.com/Phlegmelm/CRACK12
https://github.com/AureliusIvan/ubl-itel-s23
https://github.com/AureliusIvanInvenioPTL/ubl-itel-s23
https://github.com/xbxarchivr/UNISOCUnlocker
https://github.com/Forbirdden/TigerSmash
https://github.com/zenfyrdev/bootloader-unlock-wall-of-shame
https://github.com/Seriousattempts/Bootloader_Unlock_Retroid_Pocket_3Plus
https://github.com/TheGammaSqueeze/Bootloader_Unlock_Anbernic_T820
https://github.com/TomKing062/CVE-2022-38694_unlock_bootloader
https://www.nccgroup.com/research-blog/there-s-another-hole-in-your-soc-unisoc-rom-vulnerabilities/