CVE-2025-59404
7.5Flock Safety · Bravo Edge AI Compute Device
The Flock Safety Bravo Edge AI Compute Device contains an unlocked bootloader that allows for the bypass of Android Verified Boot and unauthorized modification of partitions.
Executive summary
A critical vulnerability in the Flock Safety Bravo Edge AI Compute Device allows an unauthenticated attacker to bypass security protections and modify device partitions, leading to potential full system compromise.
Vulnerability
The device ships with an unlocked bootloader, which enables an unauthenticated attacker to bypass Android Verified Boot (AVB) mechanisms. This flaw permits the direct modification of system partitions, effectively granting root-level control over the hardware.
Business impact
The ability to modify device partitions and bypass boot security presents a significant risk to the integrity and confidentiality of the data processed by the Bravo Edge device. A successful exploit could facilitate the installation of persistent malicious firmware or unauthorized surveillance tools, resulting in severe reputational damage and the loss of trust in security infrastructure. With a CVSS score of 7.5, this high-severity vulnerability requires immediate attention to prevent unauthorized physical or remote manipulation of these compute units.
Remediation
Immediate Action: Contact Flock Safety support immediately to determine if a firmware update or security configuration change is available to lock the bootloader and disable partition access.
Proactive Monitoring: Monitor device access logs for any unauthorized configuration changes or anomalous boot-time activity that might indicate an attempt to interact with the bootloader or partition structure.
Compensating Controls: Ensure physical access to all Bravo Edge devices is strictly restricted, as the current vulnerability may require physical or local network proximity to execute the bootloader bypass.
Exploitation status
Public Exploit Available: Yes, a technical research write-up (GainSec) exists detailing the mechanism for achieving a root shell on the device.
Analyst recommendation
Given the nature of this vulnerability, which fundamentally undermines the trust anchor of the device, organizations must prioritize this issue. Administrators should work closely with the vendor to verify the status of their specific hardware units and apply any available security patches as soon as they are released. If a patch is not yet available, implement strict physical and network-level isolation to prevent unauthorized access to these devices.