Description
The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1.
Published: 2026-08-19
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who can physically write to the device’s boot media to inject a specially crafted init‑table entry. This entry is parsed and executed by the Ingenic T41, T32, T40, and A1 SoC boot ROM before the system state is verified for secure boot. By performing a full‑address 32‑bit write, the attacker can alter the SRAM‑resident secure boot flag, effectively disabling the signature verification and permitting the ROM to load unsigned or modified first‑stage boot code. The result is a complete bypass of the device’s trusted boot chain, allowing execution of arbitrary firmware that can threaten confidentiality, integrity, or availability.

Affected Systems

The affected systems are Ingenic SoCs including the T41, T32, T40, and A1 families. While the vendor is not listed as a known CNA provider, the security note explicitly references that the flaw is present in the boot ROM of these devices. No specific firmware versions are provided, so any device running the default boot ROM is potentially vulnerable.

Risk and Exploitability

The flaw requires physical write access to boot media, limiting the attacker to environments where firmware can be modified, such as during manufacturing or by a malicious insider. Because EPSS data is unavailable and the vulnerability is not listed in CISA KEV, publicly available exploit data is scarce, but the impact of disabling secure boot is substantial. An attacker can replace the first‑stage boot image with malicious firmware, compromising confidentiality, integrity, and availability of the device. The flaw falls under CWE‑287, indicating an authentication bypass vulnerability.

Generated by OpenCVE AI on August 19, 2026 at 19:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied firmware update that changes the boot ROM to verify secure boot state before parsing the init table.
  • If a patch is not yet available, physically secure the boot media to prevent write access, and configure the device to boot only from protected storage locations.
  • Use hardware‑enforced secure‑boot mechanisms, such as cryptographic verification at power‑on, to ensure that unsigned firmware cannot be loaded.

Generated by OpenCVE AI on August 19, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Secure Boot Bypass via Erroneous Init Table Order in Ingenic T41/T32/T40/A1 SoCs
Weaknesses CWE-287

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-19T13:47:58.178Z

Reserved: 2026-06-05T00:00:00.000Z

Link: CVE-2026-50719

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:31.977

Modified: 2026-08-19T14:17:31.977

Link: CVE-2026-50719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T20:00:05Z

Weaknesses