Junglewise Threat Intelligence

CVE-2026-36174: GNCC GP5 plaintext information disclosure in serial console

CVE-2026-36174 · Severity: info · CVSS 4.6 · Published 2026-06-04

Technologies: GNCC GP5. Vendors: GNCC.

Executive brief

The GNCC GP5 smart camera contains a security flaw where it transmits sensitive Wi-Fi credentials in plain text through its internal hardware diagnostic port. An individual with physical access to the device could monitor these communications to steal wireless network passwords. This could lead to unauthorized access to the owner's home or business network.

Technical details

A cleartext storage and transmission vulnerability exists in the GNCC GP5 smart camera (firmware v7.1.76). During routine boot and operational sequences, the device outputs sensitive configuration data, including Wi-Fi SSIDs and passwords, to the Universal Asynchronous Receiver-Transmitter (UART) serial interface. An attacker with physical access to the device's internal components can intercept this data by connecting to the serial pins on the PCB. This requires no authentication and allows for the full compromise of the local wireless network credentials used by the device.

Affected products

  • GNCC GP5 7.1.76

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory

References

Related threats