CVE-2026-36175 Details
Description
An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments.
A vulnerability exists in the U-Boot component of GNCC GP5 cameras running firmware version 7.1.76. This issue allows physically-proximate attackers to bypass authentication and gain root access by interrupting the boot sequence and injecting a crafted string into the kernel boot arguments. The vulnerability arises from an unencrypted boot process and an unlocked UART interface, which can be exploited to modify boot arguments and access the operating system as root.
As the vendor has not provided a patch, it is recommended to isolate the device on a VLAN without internet access and consider replacing the hardware, as factory resets do not remove sensitive data, posing a risk if the device is resold.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 4, 2026CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/GNCC-GP5-T23/README.md | CISA-ADP | BundleExploitRemedyTechnical Analysis |
| https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/GNCC-GP5-T23/README.md | [email protected] | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| GNCC GP5 | 7.1.76 (semver) |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |
Volerion