CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 163

As cited

Copy frozen at (site build).

vulnerabilities

Risky Bulletin: FatFs bugs enable physical access attacks on a load of devices

Security researchers at runZero discovered seven unpatched vulnerabilities in FatFs, a widely used filesystem driver in industrial equipment and smart devices. The bugs can enable memory corruption and arbitrary code execution through a crafted filesystem image, requiring physical access to the affected device. Developers across multiple industries will need to implement patches as they become available.

Why it matters: These vulnerabilities require physical access but affect pervasive firmware, making device inventory and patching strategies critical for organizations relying on FatFs-based equipment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary