Executive brief
IGEL OS, an operating system used for thin clients and secure endpoints, contains a vulnerability that allows an attacker to bypass Secure Boot protections. By exploiting a flaw in how the system verifies digital signatures, an attacker with physical access can load a malicious root filesystem. This could allow for the persistent compromise of the device, bypassing the security measures intended to ensure only trusted software runs on the hardware.
Technical details
A vulnerability in the igel-flash-driver module of IGEL OS (versions prior to 11.01.100) stems from the improper verification of cryptographic signatures, specifically the use of a key past its expiration date (CWE-347). An attacker with physical access can exploit this to bypass Secure Boot mechanisms. By providing a crafted, unverified SquashFS image, the attacker can force the system to mount a malicious root filesystem. This vulnerability has been observed in the wild and is tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- IGEL IGEL OS before 11.01.100
Timeline
- 2025-06-05: disclosed: Initial CVE assignment and description provided by MITRE
- 2025-10-14: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
- 2025-10-14: advisory: NVD published the vulnerability details