Gigadevice is a microcontroller and firmware vendor whose vulnerabilities concentrate in its GD32 ARM-based and RISC-V processor families and their associated firmware, a modestly represented but strategically positioned component in embedded systems and IoT deployments. The observed weakness classes—resource exposure to unintended trust boundaries, improper input validation, and incorrect default permissions—reflect the access-control and configuration demands of firmware-level components. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gigadevice over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13468MEDIUM Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical | Aug 31, 2020 | 6.8 | 18 | NO | NO |
CVE-2020-13465MEDIUM The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface. | Aug 31, 2020 | 6.8 | 18 | NO | NO |
CVE-2020-13472MEDIUM The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module. | Aug 31, 2020 | 4.6 | 17 | NO | NO |
CVE-2020-13470MEDIUM Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data. | Aug 31, 2020 | 4.6 | 14 | NO | NO |
CVE-2020-13469MEDIUM The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU. | Aug 31, 2020 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gigadevice.
Media articles that mention a CVE ID that affects a product developed by Gigadevice — matched by CVE ID, not by vendor name.