Junglewise Threat Intelligence

CVE-2026-36182: GNCC GP5 weak password hashing for root account

CVE-2026-36182 · Severity: info · Published 2026-06-04

Technologies: GNCC GP5. Vendors: GNCC.

Executive brief

The GNCC GP5, an IoT device, uses an outdated and weak method for securing its administrative root password. This flaw makes it significantly easier for an unauthorized person to guess the password through automated 'brute-force' attempts. If successful, an attacker would gain full control over the device, potentially allowing them to intercept data, disrupt operations, or use the device as a foothold to attack other parts of the network.

Technical details

GNCC GP5 version v7.1.76 is vulnerable to credential recovery due to the use of a weak cryptographic hashing algorithm for protecting the root password. This implementation flaw allows an attacker with access to the password hashes (potentially via local file access or other configuration exports) to perform offline brute-force or rainbow table attacks with high efficiency. Successful exploitation results in the recovery of the plaintext root credentials, granting the attacker full administrative privileges over the IoT device. No specific patch has been confirmed in the advisory, though users should monitor for firmware updates beyond v7.1.76.

Affected products

  • GNCC GP5 v7.1.76

Timeline

  • 2026-06-04: disclosed: Initial disclosure via MITRE and NVD
  • 2026-06-04: advisory: NVD publication date

References

Related threats