
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24857 is an improper access control vulnerability (CWE-1274) affecting volatile memory containing boot code in the Universal Boot Loader (U-Boot) before version 2017.11, as well as devices using Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574, and Johnson Controls Airwall AW-75. Successful exploitation could allow a physically present attacker to execute arbitrary code on affected devices. The vulnerability was publicly disclosed on December 9–10, 2025, via a CISA ICS Advisory (ICSA-25-343-01), with an update added on March 5, 2026, to include Johnson Controls Airwall AW-75. It carries a CVSS v3.1 base score of 8.4 (High) per CISA's vendor scoring, and 7.6 (High) per NVD (CISA Advisory, Red Hat CVE).
The root cause is classified as CWE-1274 (Improper Access Control for Volatile Memory Containing Boot Code), meaning the bootloader fails to properly restrict access to volatile memory regions that hold boot code during the boot process. An attacker with physical access to the device — specifically to its USB-A ports — can interact with the bootloader environment to inject or manipulate boot code in volatile memory, ultimately achieving arbitrary code execution. The attack vector is physical (AV:P), requires no privileges or user interaction, and has low attack complexity. The vulnerability was discovered by Harvey Phillips of Amazon Element55 and reported to CISA (CISA Advisory).
Successful exploitation grants an attacker full control over the affected device at the bootloader level, with high confidentiality, integrity, and availability impact and a changed scope (per NVD scoring). An attacker could execute arbitrary code before the operating system loads, potentially installing persistent firmware-level implants, rootkits, or bootkits that survive OS reinstallation. Given that affected devices span critical infrastructure sectors including energy, healthcare, communications, and industrial control systems, compromise could have significant downstream consequences (CISA Advisory).
No known public exploitation specifically targeting this vulnerability has been reported to CISA, and the vulnerability is not exploitable remotely — physical access is required (CISA Advisory). The EPSS score is very low at approximately 0.02%, reflecting the physical access requirement and limited attacker pool. No exploit code, proof-of-concept, or threat actor attribution has been publicly identified. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report.
Konsulko, the third-party maintainer of U-Boot, recommends upgrading to U-Boot version v2025.4 or later, available at https://ftp.denx.de/pub/u-boot/. Qualcomm recommends that users with affected IPQ chips contact Qualcomm support referencing CVE-2025-24857, QPSIIR-1969, or CR4082905. For Johnson Controls Airwall AW-75 devices running U-Boot 2017.03 or earlier, install hotfix hf-3303 (available from the Tempered webhelp portal), physically secure the device to prevent USB access, and consider sealing USB-A ports with epoxy. General mitigations include ensuring physical security of all affected devices, restricting physical access to USB ports, and isolating ICS/OT networks from business networks (CISA Advisory).
The vulnerability was covered in The Hacker News' weekly security recap for December 2025, alongside other notable vulnerabilities such as Apple 0-days and WinRAR exploits, indicating moderate industry attention (The Hacker News). Red Hat published a CVE tracking page, and INCIBE (Spain's national cybersecurity agency) issued an early warning advisory. Debian maintainers also addressed the vulnerability in U-Boot package updates, as noted in community blog posts. Overall community reaction has been measured, consistent with the physical-access-only exploitation requirement limiting the urgency for most organizations.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."