Removable Media Becomes Full Control on Embedded Gear

The trust boundary is the USB stick, SD card, or update image. In devices that embed FatFs, a malformed volume can push the parser into memory corruption, so brief physical access can become code execution or a brick on systems that do not have desktop-grade memory protections. runZero disclosed seven FatFs bugs and published proof-of-concept disk images. The library sits inside firmware for cameras, industrial controllers, ATMs, kiosks, voting machines, hardware wallets, and other embedded devices, and six of the flaws have no upstream fix; only one is fixed in FatFs R0.16. The worst cases reach code execution, and some issues are also reachable through firmware updates. That leaves remediation to uneven vendor-specific patches, which will widen the gap between disclosure and real-world coverage across device lines.

Part of the PlainSec briefing for 2026-07-04

Sources