CVE-2025-59408
7.3Flock Safety · Bravo Edge AI Compute Device
The Flock Safety Bravo Edge AI Compute Device ships with Secure Boot disabled, allowing attackers to flash modified firmware onto the device without cryptographic validation.
Executive summary
A critical vulnerability in the Flock Safety Bravo Edge AI Compute Device allows for unauthorized firmware modification due to a disabled Secure Boot mechanism.
Vulnerability
The device fails to enforce Secure Boot, which permits an unauthenticated attacker to bypass integrity checks and install malicious firmware to gain root access to the compute box.
Business impact
The ability to install arbitrary firmware on an edge compute device represents a total compromise of the hardware unit. Successful exploitation allows for persistent unauthorized access, potential data exfiltration, and the ability to use the compromised device as a pivot point into the broader network environment. Given the CVSS score of 7.3, this high severity flaw poses a significant risk to organizational infrastructure and data confidentiality.
Remediation
Immediate Action: Contact Flock Safety support immediately to verify if a firmware update or remediation process exists for the Bravo Edge AI Compute Device, as no public patch is currently confirmed.
Proactive Monitoring: Monitor network traffic for unusual outbound connections originating from edge devices and review system logs for unauthorized authentication attempts or unexpected configuration changes.
Compensating Controls: Isolate affected compute devices on a restricted VLAN with strict firewall rules to prevent unauthorized external access to the device management interfaces.
Exploitation status
Public Exploit Available: Yes, a published proof of concept exists, attributed to the technical write-up provided by GainSec.
Analyst recommendation
The absence of Secure Boot on critical infrastructure devices is a severe security oversight that requires immediate attention. Security teams should prioritize the physical and network isolation of these devices until a vendor-verified firmware update is successfully applied to re-enable secure boot protections.