Skip to finding
important · Boot chain — Appliance

ShizenBox2 serial access permits a persistent root backdoor through U-Boot.

Affects

Shizen Connect ShizenBox2, an edge appliance administered through the vendor's dev-conf software and booted through U-Boot.

The shipped console had no password and allowed unrestricted rootfs reads and writes after boot interruption through the serial port.

Detail and 6 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026