CVE-2025-47827
MEDIUM KEVIGEL OS < 11 - Secure Boot Bypass via Improper Cryptographic Signature Verification
Title source: llmExploitation Summary
CVE-2025-47827 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 14, 2025. EIP tracks 1 public exploit from researchers including Zedeldi.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-47827, a Secure Boot bypass vulnerability in IGEL OS before v11 due to improper cryptographic signature verification in the `igel-flash-driver` module. The writeup includes root cause analysis, boot process diagrams, and discussions on mitigation and impact.
Description
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2025-47827, a Secure Boot bypass vulnerability in IGEL OS before v11 due to improper cryptographic signature verification in the `igel-flash-driver` module. The writeup includes root cause analysis, boot process diagrams, and discussions on mitigation and impact.
References (4)
Scores
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H