Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33243

28
FAUCET Score

CVE-2026-33243 identifies a high-severity signature verification bypass in the barebox bootloader, affecting versions from 2016.03.0 up to 2026.03.1 (and backported to 2025.09.3). This vulnerability allows an attacker to manipulate the 'hashed-nodes' property within a FIT signature, tricking the bootloader into loading unverified or malicious images. Rated 8.2 HIGH (CVSS:3.1), exploitation requires high privileges and local access, but has low attack complexity, potentially leading to complete system compromise. While the issue has been patched, there is currently no public exploit code available, it is not listed on the CISA KEV catalog, and community discussion is minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2013.07, < 2026.04CPE matchmatch criteria
cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*
2026.04CPE matchmatch criteria
cpe:2.3:a:denx:u-boot:2026.04:rc1:*:*:*:*:*:*
2026.04CPE matchmatch criteria
cpe:2.3:a:denx:u-boot:2026.04:rc2:*:*:*:*:*:*
2026.04CPE matchmatch criteria
cpe:2.3:a:denx:u-boot:2026.04:rc3:*:*:*:*:*:*
>= 2016.03.0, < 2025.09.3CPE matchmatch criteria
cpe:2.3:a:pengutronix:barebox:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.5
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 2nd percentile among its peer group of 356 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / barebox/barebox/commit/aca01795056d51060cb096f9a1ea309361743e05
Patch
github.com / barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4
PatchVendor Advisory