CVE Explorer
CVE-2025-65396
A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by inducing a read error from the SPI flash memory during the boot, by shorting a data pin of the IC to ground. An attacker can then dump the entire firmware, leading to the disclosure of sensitive information including cryptographic keys and user configurations.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 4 assertions
{"cweId":"CWE-119","description":"CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/adp/0/problemTypes/1/descriptions/0
{"cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/adp/0/problemTypes/2/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-1274","description":"CWE-1274 Improper Access Control for Volatile Memory Containing Boot Code","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"PHYSICAL","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
4 source assertions{"cweId":"CWE-119","description":"CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/adp/0/problemTypes/1/descriptions/0
{"cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/adp/0/problemTypes/2/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-1274","description":"CWE-1274 Improper Access Control for Volatile Memory Containing Boot Code","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://lessonsec.com/cve/cve-2025-65396/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7c7f9ab745488308f58c24ad832ae6b0a92c1586112ff0c8e5ce5322999f6d53 · sha256:44cd4327b68036b8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.