CVE-2025-47827

Published
View on NVD ↗
CVSS v3
4.6
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

PoC and vulnerability report for CVE-2025-47827.
GitHubGitHub
2
Python implementation of the IGEL filesystem.
GitHubGitHub