top of page
perceptive_background_267k.jpg

Universal Boot Loader (U-Boot)

Published:

9 December 2025 at 12:00:00

Alert date:

9 December 2025 at 18:02:56

Source:

cisa.gov

Click to open the original link from this advisory

CISA published an advisory for CVE-2025-24857, a critical vulnerability in Universal Boot Loader (U-Boot) affecting versions prior to 2017.11. The vulnerability involves improper access control for volatile memory containing boot code, allowing arbitrary code execution. Multiple Qualcomm IPQ chips are confirmed affected. The vulnerability has a CVSS v4 score of 8.6 and CVSS v3 score of 8.4, with low attack complexity. While not remotely exploitable, it requires physical access to the device. Konsulko recommends upgrading to U-Boot version v2025.4 or later, while Qualcomm advises affected chip users to contact support. The vulnerability was reported by Harvey Phillips from Amazon Element55.

Technical details

Mitigation steps:

Affected products:

U-Boot
Qualcomm IPQ4019
Qualcomm IPQ5018
Qualcomm IPQ5322
Qualcomm IPQ6018
Qualcomm IPQ8064
Qualcomm IPQ8074
Qualcomm IPQ9574

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page