CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-50719

mediumCVSS 6.8covered by 1 sourcefirst seen 2026-08-19
The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of SRAM-resident secure boot state prior to the verification decision. An attacker with physical write access to boot media can inject an init-table entry that disables the secure boot check, causing the ROM to accept unsigned or modified first-stage boot code. This has been hardware-validated on a secureboot-enabled T41 device; ROM analysis confirms closely related behavior on T32, T40, and A1.

⚡ Watch CVE-2026-50719

Get an email if CVE-2026-50719 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-50719

CVE.org record

Embed the live status

CVE-2026-50719 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-50719 status](https://www.csirts.com/badge/CVE-2026-50719)](https://www.csirts.com/cve/CVE-2026-50719)