Michael Koerfer
@OT_MacDonald@infosec.exchange
Human, anti-fascist, craftsman, whitehat, team science...
infosec.exchange
U-Boot, a widely used open-source bootloader, is reported to contain six security vulnerabilities that allow attackers to run malicious code or crash devices during the boot process. The flaws are in the Flattened Image Tree (FIT) signature verification mechanism, which ensures that only trusted firmware images load.
Because the vulnerabilities trigger before the operating system starts, they can bypass standard security protections and allow for persistent malware setup.
https://beyondmachines.net/event_details/u-boot-bootloader-flaws-allow-stealthy-pre-boot-code-execution-b-d-7-x-u/gD2P6Ple2L
#openwrt #cybersecurity #tplink #glinet