CVE-2018-6242
MEDIUMNVIDIA Tegra BootROM RCM - Buffer Overflow via Physical USB Access
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2018-6242. PoCs published by DavidBuchanan314, reswitched, austinhartzheim.
AI-analyzed exploit summary This repository contains a functional Android app (NXLoader) designed to exploit CVE-2018-6242, a vulnerability in Nintendo Switch's USB control request handling. The exploit leverages the Fusée Gelée coldboot vulnerability to execute arbitrary payloads via USB.
Description
Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.
Exploits (6)
This repository contains a functional Android app (NXLoader) designed to exploit CVE-2018-6242, a vulnerability in Nintendo Switch's USB control request handling. The exploit leverages the Fusée Gelée coldboot vulnerability to execute arbitrary payloads via USB.
This repository contains a proof-of-concept exploit for CVE-2018-6242 (Fusée Gelée/ShofEL2), targeting the Nintendo Switch's RCM mode via a USB-based buffer overflow. The code initializes a USB host controller, validates the connected device, and triggers the vulnerability by sending a malformed USB control request.
This is a Rust implementation of the Fusée Gelée exploit (CVE-2018-6242) targeting NVIDIA Tegra processors. It leverages a USB buffer overflow vulnerability to achieve arbitrary code execution on vulnerable devices.
This repository contains an Android application (NXLoader) that exploits CVE-2018-6242 to inject payloads into Nintendo Switch devices in RCM mode. The exploit leverages the Fusée Gelée vulnerability to execute arbitrary code on the Switch.
This repository contains a functional proof-of-concept exploit for CVE-2018-6242 (Fusée Gelée), targeting the Nintendo Switch's bootrom vulnerability. The exploit constructs a payload to trigger a stack smash via USB, leveraging the vulnerability to execute arbitrary code.
References (1)
Scores
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H