Impact
The vulnerability allows an attacker with physical write access to the device’s boot media to insert a custom init‑table entry. Ingenic T41, T32, T40, and A1 boot ROMs parse and execute this table before validating the secure‑boot state or verifying the code signature. Because the parser supports full‑address 32‑bit SRAM writes, the malicious entry can alter the secure‑boot flag stored in SRAM, effectively disabling signature checking and permitting unsigned or tampered first‑stage boot code. This results in a complete bypass of the trusted boot chain, allowing arbitrary firmware execution.
Affected Systems
Ingenic SoCs, specifically the T41, T32, T40, and A1 families, are affected. No vendor CNA is listed, and no specific firmware versions are mentioned, so any device running the stock boot ROM is potentially vulnerable.
Risk and Exploitability
The flaw requires physical write access to the boot media, limiting attackers to environments where firmware can be modified, such as during manufacturing, repair, or by a malicious insider. While the EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, disabling secure boot allows an adversary to replace the first‑stage boot image with malicious firmware, compromising confidentiality, integrity, and availability of the device. The CVSS score of 6.8 indicates a moderate severity flaw. The weakness falls under several categories: CWE‑284, CWE‑347, CWE‑474.
OpenCVE Enrichment