CVE-2026-36178

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive user data.
Configurations

No configuration.

History

22 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) La funcionalidad de restablecimiento de fábrica en GNCC GP5 v7.1.76 no logra borrar material criptográfico sensible en la partición de configuración JFFS2, posiblemente permitiendo a los atacantes recuperar y obtener datos de usuario sensibles.

05 Jul 2026, 17:17

Type Values Removed Values Added
References
  • {'url': 'http://gp5.com', 'source': 'cve@mitre.org'}

05 Jul 2026, 02:17

Type Values Removed Values Added
References
  • {'url': 'http://gncc.com', 'source': 'cve@mitre.org'}

04 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/GNCC-GP5-T23/README.md - () https://github.com/BadChemical/IoT-Vulnerability-Research-Public/blob/main/GNCC-GP5-T23/README.md -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
CWE CWE-212

04 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 15:16

Updated : 2026-07-22 20:10


NVD link : CVE-2026-36178

Mitre link : CVE-2026-36178

CVE.ORG link : CVE-2026-36178


JSON object : View

Products Affected

No product.

CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer