{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/embedded-security/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:denx:u-boot:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-74222"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["U-Boot (\u003c 2026.10-rc5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","embedded-security","denial-of-service"],"_cs_type":"advisory","_cs_vendors":["Das U-Boot"],"content_html":"\u003cp\u003eU-Boot versions prior to 2026.10-rc5 contain a critical use-after-free vulnerability located within the httpc_recv_cb() function of the lwIP (lightweight IP) wget implementation. This flaw manifests when an HTTP data storage operation fails during the download process. In this failure state, the callback incorrectly frees the connection's Protocol Control Block (PCB) but proceeds to return an ERR_BUF status instead of the required ERR_ABRT. This discrepancy allows the TCP input path to subsequently reference the previously freed memory space, resulting in memory corruption and a hard crash of the bootloader. Because this occurs during the boot process, successful exploitation results in an immediate denial-of-service condition for the affected device.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to embedded systems utilizing U-Boot for network-based boot processes. If successfully triggered, the vulnerability results in a system-wide denial-of-service, as the device becomes unable to complete the boot sequence. This is particularly relevant for hardware platforms configured to perform automated firmware updates or netboot operations via the U-Boot lwIP stack.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade U-Boot to version 2026.10-rc5 or later to receive the patch for CVE-2026-74222.\u003c/li\u003e\n\u003cli\u003eAudit network-accessible boot configurations on embedded devices to restrict access to trusted internal management subnets.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the network-based boot features or the wget functionality in the U-Boot environment until the firmware can be updated.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T22:30:13Z","date_published":"2026-09-29T22:30:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-74222/","summary":"U-Boot versions prior to 2026.10-rc5 contain a use-after-free vulnerability in the httpc_recv_cb function, which can be triggered during failed HTTP data storage to cause a bootloader crash.","title":"U-Boot Use-After-Free in lwIP wget Implementation","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-74222/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VxWorks 7","VxWorks"],"_cs_severities":["high"],"_cs_tags":["vulnerability","embedded-security","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Wind River"],"content_html":"\u003cp\u003eWind River has identified multiple security vulnerabilities affecting VxWorks 7, a widely used real-time operating system (RTOS) in embedded devices, industrial control systems, and network infrastructure. These vulnerabilities can be exploited by a local attacker to disrupt service availability through denial-of-service (DoS) conditions, execute arbitrary code with elevated privileges, or perform unauthorized disclosure and manipulation of sensitive system data. Given the pervasive use of VxWorks in critical infrastructure and embedded systems, successful exploitation could lead to significant operational disruptions. Defenders should monitor for vendor updates and patches addressing these specific vulnerabilities as documented by Wind River's security advisories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities may lead to a complete denial of service for critical embedded systems, unauthorized remote or local code execution, and data corruption or exposure. These risks are particularly acute for organizations operating within critical infrastructure, medical device manufacturing, and industrial automation sectors that rely on VxWorks 7 for operational stability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of devices running VxWorks 7 within the organization's asset inventory. Verify current firmware versions against the official Wind River security updates and apply relevant patches or mitigations provided by the vendor. Ensure that physical and local access controls for devices running VxWorks are strictly enforced to minimize the local access vector identified in this advisory.\u003c/p\u003e\n","date_modified":"2026-10-02T14:21:25Z","date_published":"2026-09-29T22:18:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wind-river-vxworks-vulnerabilities/","summary":"Multiple vulnerabilities in Wind River VxWorks 7 allow a local attacker to perform denial-of-service attacks, potentially execute arbitrary code, and disclose or manipulate sensitive data.","title":"Multiple Vulnerabilities in Wind River VxWorks 7","url":"https://feed.craftedsignal.io/briefs/2026-09-wind-river-vxworks-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Embedded-Security","version":"https://jsonfeed.org/version/1.1"}