← Back to overview

IGEL OS versions 12 before 12.7.6 and 11 before 11.11.150 contain a boot registry parameter injection vulnerability. Attackers with physical access can write malicious kernel command line parameters to an unencrypted and unsigned configuration area that is read by the signed bootloader. The injected parameters execute with boot environment privileges. Critically, the attack bypasses TPM PCR measurement checks because it does not modify the measured boot code itself. This effectively undermines Secure Boot and full-disk encryption protections on affected thin client devices. The vulnerability was publicly disclosed at DEF CON 34 as part of research into thin client cryptographic weaknesses. A proof-of-concept exploit script has been published on GitHub. IGEL has issued a security advisory (ISN-2026-19) and released patched versions of both OS branches.

Affected products

  • IGEL OS 11
  • IGEL OS 12

Related CVE's

  • CVE-2026-82017

Categories

  • Mobile & IoT
  • Operating Systems
  • Zero-Day Vulnerabilities