A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://gist.github.com/AzhariRamadhan/a5c9644861f46b1eadb1f2a15c7950fe | Exploit Third Party Advisory |
| https://github.com/AzhariRamadhan/uboot-cve | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-08-05 19:15
Updated : 2025-10-02 17:35
NVD link : CVE-2025-45512
Mitre link : CVE-2025-45512
CVE.ORG link : CVE-2025-45512
JSON object : View
Products Affected
denx
- u-boot
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
