Junglewise Threat Intelligence

CVE-2026-36180: GNCC GP5 file system integrity bypass via bind-mount attack

CVE-2026-36180 · Severity: info · Published 2026-06-04

Technologies: GNCC GP5. Vendors: GNCC.

Executive brief

The GNCC GP5, an IoT device, contains a security flaw that allows an individual with physical access to the hardware to bypass built-in file protections. By manipulating how the system mounts its storage, an attacker can modify critical system files and software that are normally protected as read-only. This could allow an attacker to alter the device's behavior or compromise its security for the duration of the current power cycle.

Technical details

The GNCC GP5 (v7.1.76) lacks sufficient runtime integrity checks, making it susceptible to a bind-mount attack. An attacker with physical access to the device can leverage this weakness to bypass read-only file system protections. By performing a bind-mount, the attacker can overlay writable directories over protected system paths, allowing for the modification of system binaries and configuration files. These modifications persist for the duration of the boot session, potentially allowing for arbitrary code execution or unauthorized configuration changes.

Affected products

  • GNCC GP5 7.1.76

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory

References

Related threats