Impact
The vulnerability is caused by a lack of runtime integrity checks in GNCC GP5, which permits a physically proximate attacker to perform a bind‑mount attack that temporarily defeats the device’s read‑only filesystem protections. During the boot session, the attacker can modify critical system files and binaries. The impact is the ability to tamper with system components, potentially altering behavior, inserting malicious code, or creating a foothold for further exploitation. This flaw represents an authorization and integrity weakness that could lead to unauthorized modification of a device’s core functions.
Affected Systems
GNCC GP5 device running firmware version 7.1.76 is affected. No other versions or vendor/product combinations are listed as impacted.
Risk and Exploitability
Exploitation requires physical proximity to the device; it is a local‑physical attack. The EPSS score is < 1% (0.00017) and the flaw is not listed in CISA’s KEV catalog. The CVSS score of 4.6 indicates a moderate overall risk. Because the attack can modify system binaries for the remainder of a boot session, the risk is high if an attacker gains access to the device, but widespread remote exploitation is unlikely without physical presence.
OpenCVE Enrichment