PT-2026-78354 · Ingenico · T32+3

CVE-2026-50719

·

Published

2026-08-19

·

Updated

2026-08-24

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ingenic T41 (affected versions not specified) Ingenic T32 (affected versions not specified) Ingenic T40 (affected versions not specified) Ingenic A1 (affected versions not specified)
Description Boot ROMs in certain SoC (System on Chip) components parse and execute an attacker-controlled init table from the SPL (Secondary Program Loader) header before verifying the secure boot state and signature. The init table parser allows full-address 32-bit write operations, which enables the modification of the secure boot state resident in the SRAM (Static Random Access Memory) before the verification decision is made. An attacker with physical write access to the boot media can inject an entry into the init table to disable the secure boot check, allowing the ROM to execute unsigned or modified first-stage boot code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50719

Affected Products

A1
T32
T40
T41