Junglewise Threat Intelligence

CVE-2025-47827: IGEL OS Secure Boot bypass in igel-flash-driver

CVE-2025-47827 · Severity: critical · CVSS 4.6 · Exploited in the wild · Published 2025-10-14

Executive brief

IGEL OS, an operating system used for thin clients and secure endpoints, contains a vulnerability that allows an attacker to bypass Secure Boot protections. By exploiting a flaw in how the system verifies digital signatures, an attacker with physical access can load a malicious root filesystem. This could allow for the persistent compromise of the device, bypassing the security measures intended to ensure only trusted software runs on the hardware.

Technical details

A vulnerability in the igel-flash-driver module of IGEL OS (versions prior to 11.01.100) stems from the improper verification of cryptographic signatures, specifically the use of a key past its expiration date (CWE-347). An attacker with physical access can exploit this to bypass Secure Boot mechanisms. By providing a crafted, unverified SquashFS image, the attacker can force the system to mount a malicious root filesystem. This vulnerability has been observed in the wild and is tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Affected products

  • IGEL IGEL OS before 11.01.100

Timeline

  • 2025-06-05: disclosed: Initial CVE assignment and description provided by MITRE
  • 2025-10-14: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
  • 2025-10-14: advisory: NVD published the vulnerability details