Junglewise Threat Intelligence

CVE-2026-36178: GNCC GP5 improper data sanitization in factory reset

CVE-2026-36178 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: GNCC GP5. Vendors: GNCC.

Executive brief

The GNCC GP5 smart camera fails to properly erase sensitive data during a factory reset. This means that if a device is sold, returned, or discarded, a new owner with physical access could potentially recover the previous user's cryptographic keys and private information. This flaw undermines the privacy and security expectations of users who believe their data has been wiped.

Technical details

The GNCC GP5 (v7.1.76) contains a flaw in its factory reset implementation where sensitive cryptographic material is not purged from the JFFS2 configuration partition. An attacker with physical access to the device can extract the flash memory or access the file system to recover these persistent secrets. This vulnerability stems from incomplete data sanitization during the reset routine. Successful exploitation allows for the recovery of sensitive user data or credentials that were intended to be deleted. No patch is currently specified in the advisory.

Affected products

  • GNCC GP5 v7.1.76

Timeline

  • 2026-06-04: disclosed: Initial disclosure via MITRE and NVD
  • 2026-06-04: advisory

References

Related threats