Junglewise Threat Intelligence

CVE-2026-36176: GNCC GP5 plaintext token disclosure in serial console

CVE-2026-36176 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: GNCC GP5. Vendors: GNCC.

Executive brief

The GNCC GP5 smart camera (v7.1.76) inadvertently leaks sensitive cloud storage credentials through its physical hardware interface. An attacker with physical access to the device can monitor the internal serial console to capture active Backblaze B2 upload tokens. These tokens could allow an unauthorized party to upload or modify data in the owner's cloud storage account.

Technical details

GNCC GP5 firmware version v7.1.76 contains an information disclosure vulnerability where pre-signed Backblaze B2 upload URLs (used for PUT requests) are logged in plaintext to the serial UART interface. An attacker with physical access to the device's internal hardware can monitor the serial console during operation to extract these active authentication tokens. Once captured, these tokens can be used to perform unauthorized file operations against the associated Backblaze B2 bucket. The attack requires physical proximity and hardware-level monitoring of the UART pins.

Affected products

  • GNCC GP5 v7.1.76

Timeline

  • 2026-06-04: disclosed: Initial disclosure via MITRE and NVD
  • 2026-06-04: advisory

References

Related threats