Undefined · Undefined · CVE-2026-30603
**Name of the Vulnerable Software and Affected Versions**
Qianniao QN-L23PA0904 version 20250721.1640
**Description**
A flaw in the firmware update mechanism allows attackers to obtain root access, install backdoors, and exfiltrate data. This is achieved by providing a specially crafted `iu.sh` script via an SD card.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.