CVE-2026-36175

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments.

Published 2026-06-04. Last modified 2026-07-22.