Blurams Flare Camera Boot Process Vulnerability Allowing Bootloader Access and Firmware Dump

Vulnerability

A vulnerability exists in the boot process of Blurams Flare Camera versions through 24.1114.151.929. It allows a physically proximate attacker to hijack the boot mechanism and access a bootloader shell via the UART interface. This exploitation involves inducing a read error from the SPI flash memory during the boot process by shorting a data pin of the integrated circuit to ground. Once access is gained, an attacker can dump the entire firmware, potentially disclosing sensitive information such as cryptographic keys and user configurations.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the bootloader, allowing for a full firmware dump. This could result in the disclosure of sensitive information, including cryptographic keys and user configurations.

Reproduction

To reproduce this vulnerability, physically access the Blurams Flare Camera and connect to the UART interface. During the boot process, short a data pin of the SPI flash memory integrated circuit to ground. This will induce a read error, disrupting the normal boot sequence. Once the bootloader access is gained, the firmware can be dumped via the UART interface.

Added: Jan 14, 2026, 5:51 PM
Updated: Jan 14, 2026, 8:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.6
remediation
0.0
relevance
2.1
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.