A buffer overflow vulnerability exists in the BootROM Recovery Mode (RCM) of certain NVIDIA Tegra mobile processors released prior to 2016. The vulnerability allows an attacker with physical access to the device's USB port and the ability to reboot the device into RCM to exploit the buffer overflow and execute arbitrary, unverified code at the BootROM level.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a standalone Python implementation of the Fusee Gelee exploit for CVE-2018-6242 against NVIDIA Tegra X1 / Nintendo Switch devices in USB RCM mode. The main exploit logic is in launcher.py, with launcher-non-annotated.py providing a shorter equivalent version; README.md documents the vulnerability, memory layout, protocol details, and usage; requirements.txt lists pyusb. The exploit is not a scanner or detector: it actively communicates with a USB device matching VID/PID 0x0955:0x7321, claims interface 0, performs the RCM handshake by reading 16 bytes from endpoint 0x81, constructs a malicious payload layout in memory, uploads it over bulk endpoint 0x01 in 0x1000-byte chunks, ensures the final transfer aligns with the high DMA buffer, and then triggers the vulnerable boot ROM memcpy via an EP0 GET_STATUS control request with an oversized length. The crafted payload includes an RCM header, an intermezzo relocator, a split user payload, and a repeated 0x40010000 stack spray so overwritten return addresses redirect execution to the relocator. Successful exploitation yields arbitrary pre-boot code execution on the device and launches the operator-provided payload binary.
This repository contains NXLoader, an Android application that allows users to inject Fusée Gelée payloads into a Nintendo Switch via USB. The exploit leverages the Fusée Gelée vulnerability (CVE-2018-6242) to gain code execution on the Switch. The repository is structured as an Android Studio project, with build files for multiple architectures (arm64-v8a, armeabi-v7a, x86) and native code in C++ (native-lib.cpp). The main exploit logic is implemented in Java (PrimaryLoader.java), which handles USB device detection, permission requests, and payload injection. The default payload is fusee.bin, but users can select other payloads. No network endpoints are used; the attack vector is local, requiring physical access to both the Android device and the Switch. The exploit is operational, providing a working payload and a user interface for payload selection and injection.
This repository contains 'NXLoader', an Android application designed to exploit the Tegra X1 bootrom vulnerability (as used in the Nintendo Switch) via USB. The app is written primarily in Java, with a native C++ component for low-level USB operations. The exploit is based on the Fusée Gelée and ShofEL2 exploits, and allows users to load arbitrary payloads (such as fusee.bin) onto a Nintendo Switch in RCM mode. The main exploit logic is implemented in 'PrimaryLoader.java', which constructs and sends a specially crafted payload to the device, then triggers the vulnerability using a native method in 'native-lib.cpp'. The app provides a user interface for selecting custom payloads and logs actions for the user. The only fingerprintable endpoint is the USB device with Vendor ID 0x0955 and Product ID 0x7321, corresponding to the Switch in RCM mode. The exploit is operational, allowing arbitrary code execution on the target device, and is not part of a larger exploit framework.
This repository is a Rust implementation of the Fusée Gelée exploit (CVE-2018-6242) targeting NVIDIA Tegra processors, most notably used in the Nintendo Switch. The exploit leverages a vulnerability in the USB Recovery Mode (RCM) protocol, allowing an attacker to send a specially crafted payload via USB to achieve arbitrary code execution on the device. The main entry point is 'src/bin/fusee-gelee.rs', which parses command-line arguments for the payload path and USB device IDs, then orchestrates the exploitation process using the 'ExploitDriver' abstraction. The core exploit logic is implemented in 'src/exploit.rs' and 'src/lib.rs', handling USB device discovery, buffer manipulation, and triggering the vulnerability via crafted control requests. The payload construction logic in 'src/payload.rs' combines a user-supplied ARM binary with an 'intermezzo' stage payload, padding and aligning the data as required by the exploit. The repository is structured for Linux hosts using libusb, and requires the target device to be in RCM mode and connected via USB. No network endpoints are involved; all exploitation is performed locally over USB. The exploit is a proof-of-concept, requiring the user to supply their own payload for execution on the target device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.