CVE-2025-24857
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-24857 is an improper access control vulnerability (CWE-1274) affecting volatile memory containing boot code in the Universal Boot Loader (U-Boot) before version 2017.11, as well as devices using Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574, and Johnson Controls Airwall AW-75. Successful exploitation could allow a physically present attacker to execute arbitrary code on affected devices. The vulnerability was publicly disclosed on December 9–10, 2025, via a CISA ICS Advisory (ICSA-25-343-01), with an update added on March 5, 2026, to include Johnson Controls Airwall AW-75. It carries a CVSS v3.1 base score of 8.4 (High) per CISA's vendor scoring, and 7.6 (High) per NVD (CISA Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-1274 (Improper Access Control for Volatile Memory Containing Boot Code), meaning the bootloader fails to properly restrict access to volatile memory regions that hold boot code during the boot process. An attacker with physical access to the device — specifically to its USB-A ports — can interact with the bootloader environment to inject or manipulate boot code in volatile memory, ultimately achieving arbitrary code execution. The attack vector is physical (AV:P), requires no privileges or user interaction, and has low attack complexity. The vulnerability was discovered by Harvey Phillips of Amazon Element55 and reported to CISA (CISA Advisory).

Impact

Successful exploitation grants an attacker full control over the affected device at the bootloader level, with high confidentiality, integrity, and availability impact and a changed scope (per NVD scoring). An attacker could execute arbitrary code before the operating system loads, potentially installing persistent firmware-level implants, rootkits, or bootkits that survive OS reinstallation. Given that affected devices span critical infrastructure sectors including energy, healthcare, communications, and industrial control systems, compromise could have significant downstream consequences (CISA Advisory).

Exploitability

No known public exploitation specifically targeting this vulnerability has been reported to CISA, and the vulnerability is not exploitable remotely — physical access is required (CISA Advisory). The EPSS score is very low at approximately 0.02%, reflecting the physical access requirement and limited attacker pool. No exploit code, proof-of-concept, or threat actor attribution has been publicly identified. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the time of this report.

Exploitation steps

  1. Physical Access: Gain physical access to a device running U-Boot prior to version 2017.11 on affected hardware (e.g., a router with a Qualcomm IPQ chip or a Johnson Controls Airwall AW-75 gateway).
  2. Connect via USB: Plug a USB device or storage medium into the device's USB-A port to interact with the bootloader environment during the boot sequence.
  3. Interrupt Boot Process: Access the U-Boot console (e.g., via serial/console port or USB) and interrupt the normal boot sequence to gain bootloader shell access.
  4. Manipulate Volatile Memory: Exploit the improper access control to read from or write arbitrary code into volatile memory regions containing boot code, bypassing expected access restrictions.
  5. Execute Arbitrary Code: Inject a malicious payload (e.g., a modified kernel image, bootkit, or persistent implant) into the boot process, achieving code execution before the OS loads and potentially establishing persistent, firmware-level compromise (CISA Advisory).

Indicators of compromise

  • Physical: Evidence of unauthorized physical access to device USB-A ports (e.g., tampered port seals, epoxy, or physical security logs showing access).
  • Logs: Unexpected or anomalous U-Boot console output during boot; boot log entries showing interrupted or modified boot sequences; console port activity logs showing unauthorized sessions.
  • File System / Firmware: Unexpected changes to bootloader version or firmware integrity checksums; presence of unknown or unsigned boot images; firmware differing from vendor-supplied baseline.
  • Process/Behavior: Device booting into an unexpected OS or environment; OS-level anomalies consistent with a compromised bootloader (e.g., disabled secure boot, unexpected kernel modules loaded at startup) (CISA Advisory).

Mitigation and workarounds

Konsulko, the third-party maintainer of U-Boot, recommends upgrading to U-Boot version v2025.4 or later, available at https://ftp.denx.de/pub/u-boot/. Qualcomm recommends that users with affected IPQ chips contact Qualcomm support referencing CVE-2025-24857, QPSIIR-1969, or CR4082905. For Johnson Controls Airwall AW-75 devices running U-Boot 2017.03 or earlier, install hotfix hf-3303 (available from the Tempered webhelp portal), physically secure the device to prevent USB access, and consider sealing USB-A ports with epoxy. General mitigations include ensuring physical security of all affected devices, restricting physical access to USB ports, and isolating ICS/OT networks from business networks (CISA Advisory).

Community reactions

The vulnerability was covered in The Hacker News' weekly security recap for December 2025, alongside other notable vulnerabilities such as Apple 0-days and WinRAR exploits, indicating moderate industry attention (The Hacker News). Red Hat published a CVE tracking page, and INCIBE (Spain's national cybersecurity agency) issued an early warning advisory. Debian maintainers also addressed the vulnerability in U-Boot package updates, as noted in community blog posts. Overall community reaction has been measured, consistent with the physical-access-only exploitation requirement limiting the urgency for most organizations.

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7867HIGH7.8
  • Linux Debian logoLinux Debian
  • udisks2-lsm
NoYesAug 06, 2026
CVE-2026-71554MEDIUM5.3
  • Python logoPython
  • python-h2
NoYesAug 06, 2026
CVE-2026-71439MEDIUM5.3
  • JavaScript logoJavaScript
  • mermaid
NoYesAug 06, 2026
CVE-2026-71498MEDIUM5.1
  • JavaScript logoJavaScript
  • re2
NoYesAug 06, 2026
CVE-2026-71497MEDIUM4.7
  • Java logoJava
  • jsoup
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management