Junglewise Threat Intelligence

CVE-2026-36175: GNCC GP5 authentication bypass in U-Boot

CVE-2026-36175 · Severity: info · Published 2026-06-04

Technologies: GNCC GP5. Vendors: GNCC.

Executive brief

The GNCC GP5, an IoT device, contains a security flaw in its bootloader component. An attacker with physical access to the device can interrupt the startup process to bypass security controls and gain full administrative (root) access. This allows the attacker to take complete control of the device, potentially compromising any data it handles or using it as a foothold in a local network.

Technical details

A vulnerability in the U-Boot bootloader of the GNCC GP5 (v7.1.76) allows for an authentication bypass via the serial console or physical interface. By interrupting the standard boot sequence, an attacker can modify the kernel boot arguments (bootargs). Specifically, injecting a crafted string such as 'init=/bin/sh' into the boot parameters allows the attacker to spawn a root shell instead of the intended initialization process. This grants full system-level access to the underlying Linux operating system without requiring valid credentials.

Affected products

  • GNCC GP5 v7.1.76

Timeline

  • 2026-06-04: disclosed: Initial disclosure via NVD and researcher GitHub repository.

References

Related threats