CVE-2026-50211
Leftover Engineering Diagnostics Write Access in Retail Software
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: 8fc372e3-d9c5-46e4-9410-38469745c639
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-134 | The product uses a function that accepts a format string as an argument, but the format string originates from an external source. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves leftover engineering diagnostics and factory-level diagnostic software that remain exposed on retail builds of a product. Because of this exposure, malicious applications can gain write privileges to internal Non-Volatile Random-Access Memory (NVRAM) registers.
How can this vulnerability impact me? :
The vulnerability allows malicious apps to write to internal NVRAM registers, which could lead to unauthorized modification of critical device settings or data stored in NVRAM. This can compromise device integrity, potentially causing malfunction, data corruption, or enabling further attacks.