CVE-2024-44754

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut M2 product via USB.

Published 2025-02-28. Last modified 2026-07-05.