Ingenic T31 SoC 的引导程序(boot ROM)在验证通过闪存启动(flash-boot)时,仅将 RSA 签名输出的单个 32 位字与 SHA-256 载荷摘要的单个 32 位字进行比较,而非对整个数据进行完整比对。这种设计缺陷使得攻击者只要具备对启动介质的物理写入权限,即可伪造经过篡改的 Secondary Program Loader(SPL,次要程序加载器)镜像,从而绕过安全启动验证,且无需拥有原始设备制造商(OEM)的签名密钥。每次伪造尝试的成功概率约为 2/3。该漏洞已通过逆向工程、针对厂
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-4996 | 5.3 MEDIUM | mruby bigint.c udiv floating point comparison with incorrect operator |
| CVE-2026-76014 | 3.3 LOW | BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference |
| CVE-2026-51367 | Bottinelli Informatica Vedo Suite 安全漏洞 | |
| CVE-2026-51366 | Bottinelli Informatica Vedo Suite 安全漏洞 | |
| CVE-2026-50719 | 芯驰T41/T32/T40/A1 SoC安全启动漏洞 | |
| CVE-2026-71694 | BOOM v1.2远程代码执行漏洞 |
No comments yet