GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 04 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Plaintext Exposure of Backblaze B2 Upload Tokens in GNCC GP5 | |
| Weaknesses | CWE-200 |
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T14:14:47.896Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36176
No data.
Status : Deferred
Published: 2026-06-04T15:16:51.410
Modified: 2026-06-04T15:41:35.193
Link: CVE-2026-36176
No data.
OpenCVE Enrichment
Updated: 2026-06-04T15:30:17Z
Weaknesses