CVE-2026-36178

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive user data.
Configurations

No configuration.

History

04 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/GNCC-GP5-T23/README.md - () https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/GNCC-GP5-T23/README.md -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
CWE CWE-212

04 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 15:16

Updated : 2026-06-04 16:16


NVD link : CVE-2026-36178

Mitre link : CVE-2026-36178

CVE.ORG link : CVE-2026-36178


JSON object : View

Products Affected

No product.

CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer