An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-288 |
|
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Physically Proximate Attackers Bypass Authentication to Gain Root via U‑Boot Boot Argument Injection | |
| Weaknesses | CWE-640 CWE-767 |
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T16:06:42.903Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36175
Updated: 2026-06-04T16:05:09.203Z
Status : Deferred
Published: 2026-06-04T15:16:51.260
Modified: 2026-06-04T15:41:35.193
Link: CVE-2026-36175
No data.
OpenCVE Enrichment
Updated: 2026-06-04T16:00:17Z