Vulnerabilities · 73 days ago
The trust boundary is the USB stick, SD card, or update image. In devices that embed FatFs, a malformed volume can push the parser into memory corruption, so brief physical access can become code execution or a brick on systems that do not have desktop-grade memory protections.
runZero disclosed seven FatFs bugs and published proof-of-concept disk images. The library sits inside firmware for cameras, industrial controllers, ATMs, kiosks, voting machines, hardware wallets, and other embedded devices, and six of the flaws have no upstream fix; only one is fixed in FatFs R0.16. The worst cases reach code execution, and some issues are also reachable through firmware updates.
That leaves remediation to uneven vendor-specific patches, which will widen the gap between disclosure and real-world coverage across device lines.
CVEs in this update
7 CVEs
0 critical · 3 high · 4 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-6687 · 7.6 HIGH
Highest EPSS: CVE-2026-6687 · 0.35%
1 source covering this story
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
runZero says six FatFs bugs lack upstream fixes; PoC disk images are public, but no attacks have been reported since July 1.
Part of the PlainSec briefing for 2026-07-04