Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-50720

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ingenic T31 SoC 的引导程序(boot ROM)在验证通过闪存启动(flash-boot)时,仅将 RSA 签名输出的单个 32 位字与 SHA-256 载荷摘要的单个 32 位字进行比较,而非对整个数据进行完整比对。这种设计缺陷使得攻击者只要具备对启动介质的物理写入权限,即可伪造经过篡改的 Secondary Program Loader(SPL,次要程序加载器)镜像,从而绕过安全启动验证,且无需拥有原始设备制造商(OEM)的签名密钥。每次伪造尝试的成功概率约为 2/3。该漏洞已通过逆向工程、针对厂

AI Predicted 8.1 Difficulty: Moderate EPSS 0.15% · P5

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50720

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data. This allows an attacker with physical write access to boot media to forge modified SPL (Secondary Program Loader) images that pass secure boot verification without possession of the OEM signing key. Each forgery attempt succeeds with approximately 2/3 probability. This has been validated via reverse engineering, software emulation against vendor-signed images, and end-to-end hardware acceptance of a forged firmware image on a Wyze Video Doorbell v2 (T31X).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-50720

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-50720

登录查看更多情报信息。

Vendor Advisories for CVE-2026-50720 (1)

Same Patch Batch · n/a · 2026-08-19 · 7 CVEs total

CVE-2022-4996 5.3 MEDIUM mruby bigint.c udiv floating point comparison with incorrect operator
CVE-2026-76014 3.3 LOW BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference
CVE-2026-51367 Bottinelli Informatica Vedo Suite 安全漏洞
CVE-2026-51366 Bottinelli Informatica Vedo Suite 安全漏洞
CVE-2026-50719 芯驰T41/T32/T40/A1 SoC安全启动漏洞
CVE-2026-71694 BOOM v1.2远程代码执行漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-50720

No comments yet


Leave a comment