Impact
The vulnerability resides in the U‑Boot component of GNCC GP5 firmware. Attackers who can physically approach the device can interrupt the boot sequence and inject a specially crafted string into the kernel boot arguments. This bypasses the device’s authentication mechanism and grants the attacker root privileges, allowing them to read, modify, or delete any data on the system and potentially render the device inoperable.
Affected Systems
The affected product is GNCC GP5 running firmware version 7.1.76. No other vendor or product information is provided, and physical proximity is required for exploitation.
Risk and Exploitability
The CVSS score is 6.8 and EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires direct physical access and knowledge of the boot injection technique, the likelihood of exploitation in the wild is uncertain, but the impact of a successful attack is severe due to the full root control it grants.
OpenCVE Enrichment