What is CVE-2026-50720?
A vulnerability in the Ingenic T31 SoC boot ROM (CVE-2026-50720) allows attackers with physical write access to the boot media to forge modified firmware due to insufficient RSA signature verification, which compares only a single 32-bit word. This can lead to arbitrary code execution on affected devices. A microcode patch from the vendor is required.
Azərbaycanca: Ingenic T31 SoC-nin boot ROM flash-boot yoxlama mexanizmindəki boşluq (CVE-2026-50720) RSA imzası ilə SHA-256 həzminin yalnız bir 32-bitlik hissəsini müqayisə etdiyi üçün, fiziki yazma icazəsi olan təcavüzkar yükləmə mediasına saxta proqram təminatı yerləşdirə bilər. Bu, təsirlənmiş cihazlarda ixtiyari kod icrasına səbəb olur. İstehsalçı tərəfindən mikrokod yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What does an attacker need to exploit CVE-2026-50720?
The attacker must have physical write access to the boot media.
What is the root cause of this vulnerability in the Ingenic T31 SoC?
The RSA signature verification compares only a single 32-bit word of the SHA-256 hash, leading to insufficient validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.