5.4
CVE-2025-59402
- EPSS 0.03%
- Veröffentlicht 25.09.2025 21:15:31
- Zuletzt bearbeitet 23.10.2025 18:07:25
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Flocksafety ≫ Bravo Compute Box Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.069 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.4 | 0.7 | 4.7 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
|
CWE-616 Incomplete Identification of Uploaded File Variables (PHP)
The PHP application uses an old method for processing uploaded files by referencing the four global variables that are set for each file (e.g. $varname, $varname_size, $varname_name, $varname_type). These variables could be overwritten by attackers, causing the application to process unauthorized files.