Skip to finding
important · Boot chain — Marine

A signed-looking update can install attacker-modified software on one Lowrance HDS Live hardware revision.

Affects

A late-2022 i.MX 8M Plus hardware revision of the Lowrance HDS Live marine multifunction display running Navico NOS

With physical access, an attacker supplies a crafted microSD update. The signed outer updater selects an inner script without verifying its generated GPG signature.

Detail and 1 source

The researcher used that gap to replace the root filesystem and execute code before most of the operating system starts. No vendor remediation was found.

Chain to watch
Prepare a modified nested update on microSD→↓Have the device accept the signed outer updater→↓Run the unverified inner update script→↓Replace the root filesystem and execute attacker code→↓The commercial model identifiers, affected firmware range and status in current releases are not public.
Unverified chainCompare current updater packages for both processor-board revisions and verify every nested script before execution.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026