Executive brief
Actions Semiconductor Media Player Utilities is a firmware update tool used for MP3/MP4 players and portable media devices. The tool fails to validate firmware images before flashing them to the device, allowing an attacker with physical USB access to inject malicious firmware that persists across factory resets and cannot be detected by users. This could allow the device to be converted into a spyware platform or permanently disabled.
Technical details
The vulnerability is insufficient verification of data authenticity (CWE-345) in the firmware update mechanism of Actions Semiconductor Media Player Utilities v.4.46. The Production.dll and RdiskUpgrade.exe components perform no cryptographic validation, checksum verification, or signature checks on firmware images before writing them to NAND flash. An attacker with physical USB access can execute arbitrary firmware by launching RdiskUpgrade.exe with a crafted Upgrade.ini and firmware image, with no authentication required. The compromise is permanent and survives factory reset, providing persistent code execution and the ability to reprogram the device as a BadUSB, keyboard emulation attack platform, or surveillance implant.
Affected products
- Actions Semiconductor Co. Ltd Media Player Utilities 4.46
Timeline
- 2026-02-25: disclosed: CVE request submitted to MITRE (service request 1998127)
- 2026-06-15: advisory: CVE-2026-36433 assigned by MITRE CVE Assignment Team
- 2026-09-05: disclosed: Public advisory published by ByteScan Security Research Lab