PT-2026-2919 · Blurams · Blurams Flare Camera

Published

2026-01-14

·

Updated

2026-01-15

·

CVE-2025-65396

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Blurams Flare Camera versions 24.1114.151.929 and earlier
Description A flaw exists in the boot process of the Blurams Flare Camera that allows a nearby attacker to take control of the boot mechanism and obtain a bootloader shell through the UART interface. This is accomplished by causing a read error from the SPI flash memory during boot by shorting a data pin of the IC to ground. Successful exploitation allows an attacker to extract the entire firmware, potentially exposing sensitive data like cryptographic keys and user settings.
Recommendations Versions prior to 24.1114.151.929 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2025-65396

Affected Products

Blurams Flare Camera