Digest
HIGH

Dell BIOS Passwords Recoverable Due to Weak XOR Encryption (CVE-2026-40639)

A joint discovery by MDSec and AmberWolf revealed a critical vulnerability (CVE-2026-40639) in Dell BIOS password storage. Dell stores BIOS administrator passwords using weak XOR encryption, allowing recovery from the SPI flash. This flaw enables attackers with physical access to easily bypass BIOS security, potentially gaining control over system boot processes and data.

← Back to the feed

Trending Tags