CVE-2026-30603
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, and exfiltrate data via supplying a crafted iu.sh script contained in an SD card.
Published 2026-04-02. Last modified 2026-07-24.