GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-312 | |
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Plaintext Exposure of Backblaze B2 Upload Tokens in GNCC GP5 | |
| Weaknesses | CWE-200 |
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T15:52:09.566Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36176
Updated: 2026-06-04T15:50:22.473Z
Status : Deferred
Published: 2026-06-04T15:16:51.410
Modified: 2026-06-04T17:16:32.373
Link: CVE-2026-36176
No data.
OpenCVE Enrichment
Updated: 2026-06-04T15:30:17Z