courk.cc Laser Fault Injection Vulnerability in RP2350 Microcontroller
Article Content
- •Ledger Donjon exploited RP2350's Secure Boot using laser fault injection.
- •The attack requires $250,000 in lab equipment and physical access to the chip.
- •Raspberry Pi acknowledged the vulnerability but deemed it non-critical for a chip respin.
Researchers from Ledger Donjon successfully exploited a vulnerability in the RP2350 microcontroller, allowing them to bypass its Secure Boot feature and access secret data stored in One-Time Programmable (OTP) memory. This attack utilized photon-emission microscopy and laser fault injection techniques, requiring approximately $250,000 worth of specialized equipment and physical access to the chip. The RP2350's security features, including secure boot and permanent debug-disable settings, were designed to prevent such exploits. However, the researchers demonstrated that targeted laser pulses could manipulate specific registers to restore debug access. Raspberry Pi acknowledged the findings and confirmed that while the vulnerability exists, it does not warrant a respin of the chip due to the attack's destructive nature and high resource requirements. The RP2350 Hacking Challenge initiated by Raspberry Pi aimed to encourage researchers to test the security of the microcontroller, leading to this discovery. The current status indicates that while the vulnerability is known, it requires significant resources to exploit effectively.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Ledger Donjon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…