{"apiVersion":"1.0","identifier":"CVE-2026-50719","description":"The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1.","publishedAt":"2026-08-19T14:17:31","lastModifiedAt":"2026-08-24T20:16:45","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-50719","cvssScore":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00105,"riskScore":0.69,"affectedProduct":"Ingenic SoC Boot ROM","affectedVersions":"unknown","vulnerabilityType":"Firmware","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-50719","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-50719","en":"https://www.redsauce.net/en/cves/CVE-2026-50719","fr":"https://www.redsauce.net/fr/cves/CVE-2026-50719","pt":"https://www.redsauce.net/pt/cves/CVE-2026-50719","de":"https://www.redsauce.net/de/cves/CVE-2026-50719","sk":"https://www.redsauce.net/sk/cves/CVE-2026-50719","el":"https://www.redsauce.net/el/cves/CVE-2026-50719"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-50719"}}