CVE-2025-59402 affects Flock Safety Bravo Edge AI Compute Devices, specifically the BRAVO_00.00_local_20241017 firmware, by allowing the default Thundercomm TurboX 6490 Firehose loader to be accepted in EDL/QDL mode. This medium-severity vulnerability (CVSS 5.4) requires physical access to the device (AV:P) but no user interaction (UI:R) to enable attackers to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls, leading to high impact on integrity and low impact on confidentiality and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:flocksafety:bravo_compute_box_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.