Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

DENX Software Engineering Das U-Boot Signature Verification Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in the bootloader of DENX Software Engineering Das U-Boot version 1.1.3, due to a lack of signature verification. This flaw allows attackers to install manipulated firmware files, which can lead to arbitrary code execution. The vulnerability was identified through static analysis of a U-Boot binary used in embedded systems, potentially on Raspberry Pi-based platforms.

Impact

Exploitation of this vulnerability could result in arbitrary code execution, unauthorized firmware uploads, and firmware downgrades to versions with known vulnerabilities. Additionally, this could lead to a persistence and supply chain compromise.

Reproduction

The vulnerability can be reproduced by exploiting the insecure update mechanism. After connecting to the device's serial interface, the absence of secure boot checks can be verified. Once confirmed, the U-Boot firmware can be replaced with a crafted image using an external flasher that writes the modified U-Boot version into the device's SPI flash.

Added: Aug 5, 2025, 7:17 PM
Updated: Aug 5, 2025, 9:37 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
4.6
remediation
0.0
relevance
0.3
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.