less on sec

exploring, hacking and breaking stuff


CVE-2025-65396: SPI Fault Enables Bootloader Access and Firmware Dump in Blurams Flare Camera

A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by inducing a read error from the SPI flash memory during the boot, by shorting a data pin of the IC to ground. An attacker can then dump the entire firmware, leading to the disclosure of sensitive information including cryptographic keys and user configurations.

Disclosure timeline

23/09/2025 First contacted with vendor
08/10/2025 Vulnerability report submitted to vendor
11/10/2025 Vulnerabilities confirmed
31/10/2025 Requested CVE IDs
29/11/2025 CVE IDs Reserverd
14/01/2026 Disclosure