firmware
85 articles with this tag
CRITICAL
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
LOW
MEDIUM
HIGH
HIGH
MEDIUM
INFO
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
INFO
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
INFO
HIGH
MEDIUM
MEDIUM
INFO
CRITICAL
HIGH
HIGH
INFO
HIGH
MEDIUM
INFO
HIGH
MEDIUM
INFO
INFO
INFO
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
INFO
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
INFO
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
LOW
MEDIUM
HIGH
It's More Secure When It's Disabled - PSW #943
Cybersecurity Insiders: AI Infrastructure’s Firmware Problem Is Bigger Than Any Single Vendor
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
[NEU] [mittel] Insyde UEFI Firmware und Cisco UCS (UEFI Shell Secure Boot): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
CareCam Pro IP Cameras
VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
The £3 WiFi Extender With a Backdoor in Every Unit
Cybersecurity Insiders: AI Infrastructure’s Firmware Problem Is Bigger Than Any Single Vendor
[NEU] [niedrig] Insyde UEFI Firmware: Schwachstelle ermöglicht nicht spezifizierten Angriff
[NEU] [mittel] Dell BIOS: Schwachstelle ermöglicht Manipulation von Daten
[UPDATE] [hoch] Nvidia Treiber: Mehrere Schwachstellen
[NEU] [mittel] Axis Axis OS: Mehrere Schwachstellen
[NEU] [mittel] Moxa Switch (EDS-510A Series, ICS-G7826A Series, und SDS Series): Schwachstelle ermöglicht Denial of Service
Reproducible ESP32 Firmware Development with Docker and Docker Sandboxes
[NEU] [hoch] Insyde UEFI Firmware (InsydeH2O): Schwachstelle ermöglicht Codeausführung
CVE-2026-68199 wifi: ath6kl: fix OOB access from firmware ADDBA window size
CVE-2026-68192 wifi: brcmfmac: make release_scratchbuffers idempotent
Zbtlink denies backdoor claims amid firmware download pause
[NEU] [hoch] Cisco Integrated Management Controller: Mehrere Schwachstellen
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Forgotten Bootloaders Expose Secure Boot Blind Spot
Six U-Boot vulnerabilities could allow stealthy firmware attacks
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
[UPDATE] [hoch] EDK2 NetworkPkg IP stack implementation: Mehrere Schwachstellen
The Two BIOS Passwords Everyone Confuses
CVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown types
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
RHSA-2026:36721: Moderate: edk2 security, bug fix, and enhancement update
[NEU] [mittel] Dell Computer: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
CubeSpace CW0057 Reaction Wheel
VU#226679: Microsoft WinRE allows for bypass of UEFI/BIOS password enforcement
VU#457458: Vendor-signed UEFI applications found vulnerable to Secure Boot bypass
Schneider Electric EasyLogic T150 and Saitel DP
BTS #76 - Binwalk, Brickstorm, AI Model Madness
Microsoft has mostly repaired a flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet
[UPDATE] [mittel] AMD Prozessoren: Schwachstelle ermöglicht Manipulation von Daten
[UPDATE] [mittel] Intel Firmware: Schwachstelle ermöglicht Denial of Service
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
XCharge C6
[NEU] [hoch] AMD Chipsätze: Mehrere Schwachstellen
[UPDATE] [hoch] Insyde UEFI Firmware: Schwachstelle ermöglicht Codeausführung
RHSA-2026:18465: Important: edk2 security update
[NEU] [mittel] AMD Prozessoren (EPYC und EPYC Embedded): Mehrere Schwachstellen
[NEU] [mittel] Intel Server Firmware Update Utility Software: Schwachstelle ermöglicht Privilegieneskalation
BTS #73 - Uncovering Firmware Risks: From Y2K to Modern Malware
Zero Motorcycles Firmware
Iran claims US used backdoors to knock out networking equipment during war
BTS #72 - AI-Powered Firmware Hacking: The Future of Vulnerability Discovery
CVE-2026-31426 ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()
BTS #72 - AI-Powered Firmware Hacking: The Future of Vulnerability Discovery
Flawed Cisco update threatens to stop APs from getting further patches
Anviz Multiple Products
Bringing Rust to the Pixel Baseband
[NEU] [hoch] Kyocera Printer: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
[UPDATE] [hoch] QNAP NAS Software und Anwendungen: Mehrere Schwachstellen
[UPDATE] [mittel] AMD Prozessor: Schwachstelle ermöglicht das Umgehen von Sicherheitsmaßnahmen
BTS #70 - How Cheap KVMs Could Be Your Network's Weak Link
TP-Link Patches Archer NX Auth Bypass, Still Faces Security Lawsuit
Cisco IOS XE Software for Cisco Catalyst and Rugged Series Switches Secure Boot Bypass Vulnerability
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Mehrere Schwachstellen
[NEU] [mittel] Phoenix Contact FL SWITCH: Mehrere Schwachstellen
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
InfoRiskToday: Cheap and Dangerous: IP KVMs Carry Flaws
The Stack: 4 KVM vendors, 9 vulns – including an unfixed CVSS 9.8
[UPDATE] [mittel] TianoCore EDK2: Schwachstelle ermöglicht Offenlegung von Informationen
CSMWrap: make UEFI-only systems boot BIOS-based operating systems
[UPDATE] [mittel] TianoCore EDK2: Schwachstelle ermöglicht Offenlegung von Informationen
[UPDATE] [hoch] TianoCore EDK2: Schwachstelle ermöglicht Codeausführung
[NEU] [hoch] Intel IPU, UEFI Reference Firmware: Mehrere Schwachstellen
[UPDATE] [hoch] Intel Ethernet Controller: Mehrere Schwachstellen
From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024
Eclypsium @ RSAC 2026
Rapid Response: Zimperium's Zero Day Coverage of Keenadu — A Firmware-Level Android Backdoor That Escapes Traditional Defenses
Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates
New Keenadu backdoor found in Android firmware, Google Play apps
Firmware-level Android backdoor found on tablets from multiple manufacturers
Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets
[UPDATE] [mittel] Insyde UEFI Firmware: Mehrere Schwachstellen ermöglichen Codeausführung
No Legs, No Problem: Dumping BGA MCP NAND Flash
[UPDATE] [mittel] Insyde UEFI Firmware: Mehrere Schwachstellen
[NEU] [hoch] Intel Firmware: Mehrere Schwachstellen ermöglichen Privilegieneskalation