Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gncc
Gncc gp5 |
|
| Vendors & Products |
Gncc
Gncc gp5 |
Thu, 04 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Plaintext Exposure of Backblaze B2 Upload Tokens via Serial Console |
Thu, 04 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Plaintext Exposure of Backblaze B2 Upload Tokens in GNCC GP5 | |
| Weaknesses | CWE-200 |
Thu, 04 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-312 | |
| Metrics |
cvssV3_1
|
Thu, 04 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Plaintext Exposure of Backblaze B2 Upload Tokens in GNCC GP5 | |
| Weaknesses | CWE-200 |
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T15:52:09.566Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36176
Updated: 2026-06-04T15:50:22.473Z
Status : Deferred
Published: 2026-06-04T15:16:51.410
Modified: 2026-06-04T17:16:32.373
Link: CVE-2026-36176
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:09:27Z