CVE-2025-59408
HIGH EPSS 14.2%
Published Sep 25, 20259mo ago · Modified Jun 17, 20261w ago
7.3 CVSS 3.1
Published Sep 25, 2025 9mo ago
Last Modified Jun 17, 2026 1w ago
Description
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability Low
Threat Intelligence
EPSS Exploit Probability
14.2% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-327
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| flocksafety | bravo_compute_box_firmware | * | any |
References 4
- gainsec.com https://gainsec.com/2025/09/19/root-from-the-coop-device-3-root-shell-on-flock-safetys-bravo-compute-box/
- gainsec.com https://gainsec.com/wp-content/uploads/2025/09/Root-from-the-Coop-Device-3_-Root-Shell-on-Flock-Safetys-Bravo-Compute-Box-GainSec.pdf
- flocksafety.com https://www.flocksafety.com/products
- flocksafety.com https://www.flocksafety.com/products/license-plate-readers
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.