firmware
63 articles with this tag
HIGH
HIGH
HIGH
HIGH
MEDIUM
INFO
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
INFO
HIGH
MEDIUM
MEDIUM
INFO
CRITICAL
HIGH
HIGH
INFO
HIGH
MEDIUM
INFO
HIGH
MEDIUM
INFO
INFO
INFO
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
INFO
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
INFO
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
LOW
MEDIUM
HIGH
Forgotten Bootloaders Expose Secure Boot Blind Spot
Six U-Boot vulnerabilities could allow stealthy firmware attacks
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
[UPDATE] [hoch] EDK2 NetworkPkg IP stack implementation: Mehrere Schwachstellen
The Two BIOS Passwords Everyone Confuses
CVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown types
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
RHSA-2026:36721: Moderate: edk2 security, bug fix, and enhancement update
[NEU] [mittel] Dell Computer: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
CubeSpace CW0057 Reaction Wheel
VU#226679: Microsoft WinRE allows for bypass of UEFI/BIOS password enforcement
VU#457458: Vendor-signed UEFI applications found vulnerable to Secure Boot bypass
Schneider Electric EasyLogic T150 and Saitel DP
BTS #76 - Binwalk, Brickstorm, AI Model Madness
Microsoft has mostly repaired a flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet
[UPDATE] [mittel] AMD Prozessoren: Schwachstelle ermöglicht Manipulation von Daten
[UPDATE] [mittel] Intel Firmware: Schwachstelle ermöglicht Denial of Service
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
XCharge C6
[NEU] [hoch] AMD Chipsätze: Mehrere Schwachstellen
[UPDATE] [hoch] Insyde UEFI Firmware: Schwachstelle ermöglicht Codeausführung
RHSA-2026:18465: Important: edk2 security update
[NEU] [mittel] AMD Prozessoren (EPYC und EPYC Embedded): Mehrere Schwachstellen
[NEU] [mittel] Intel Server Firmware Update Utility Software: Schwachstelle ermöglicht Privilegieneskalation
BTS #73 - Uncovering Firmware Risks: From Y2K to Modern Malware
Zero Motorcycles Firmware
Iran claims US used backdoors to knock out networking equipment during war
BTS #72 - AI-Powered Firmware Hacking: The Future of Vulnerability Discovery
CVE-2026-31426 ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()
BTS #72 - AI-Powered Firmware Hacking: The Future of Vulnerability Discovery
Flawed Cisco update threatens to stop APs from getting further patches
Anviz Multiple Products
Bringing Rust to the Pixel Baseband
[NEU] [hoch] Kyocera Printer: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
[UPDATE] [hoch] QNAP NAS Software und Anwendungen: Mehrere Schwachstellen
[UPDATE] [mittel] AMD Prozessor: Schwachstelle ermöglicht das Umgehen von Sicherheitsmaßnahmen
BTS #70 - How Cheap KVMs Could Be Your Network's Weak Link
TP-Link Patches Archer NX Auth Bypass, Still Faces Security Lawsuit
Cisco IOS XE Software for Cisco Catalyst and Rugged Series Switches Secure Boot Bypass Vulnerability
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Mehrere Schwachstellen
[NEU] [mittel] Phoenix Contact FL SWITCH: Mehrere Schwachstellen
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
InfoRiskToday: Cheap and Dangerous: IP KVMs Carry Flaws
The Stack: 4 KVM vendors, 9 vulns – including an unfixed CVSS 9.8
[UPDATE] [mittel] TianoCore EDK2: Schwachstelle ermöglicht Offenlegung von Informationen
CSMWrap: make UEFI-only systems boot BIOS-based operating systems
[UPDATE] [mittel] TianoCore EDK2: Schwachstelle ermöglicht Offenlegung von Informationen
[UPDATE] [hoch] TianoCore EDK2: Schwachstelle ermöglicht Codeausführung
[NEU] [hoch] Intel IPU, UEFI Reference Firmware: Mehrere Schwachstellen
[UPDATE] [hoch] Intel Ethernet Controller: Mehrere Schwachstellen
From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024
Eclypsium @ RSAC 2026
Rapid Response: Zimperium's Zero Day Coverage of Keenadu — A Firmware-Level Android Backdoor That Escapes Traditional Defenses
Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates
New Keenadu backdoor found in Android firmware, Google Play apps
Firmware-level Android backdoor found on tablets from multiple manufacturers
Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets
[UPDATE] [mittel] Insyde UEFI Firmware: Mehrere Schwachstellen ermöglichen Codeausführung
No Legs, No Problem: Dumping BGA MCP NAND Flash
[UPDATE] [mittel] Insyde UEFI Firmware: Mehrere Schwachstellen
[NEU] [hoch] Intel Firmware: Mehrere Schwachstellen ermöglichen Privilegieneskalation