← BACK TO FEED
TAG

embedded security1 articles

Seven Unpatched Flaws in a Tiny Filesystem Library Put Millions of Embedded Devices at Risk

Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a widely used filesystem library embedded in millions of devices including security cameras, drones, industrial controllers, and crypto wallets. The most serious flaws can allow an attacker with physical access — such as inserting a malicious USB drive or SD card — to corrupt device memory and execute arbitrary code, with no upstream fixes available for six of the seven bugs due to an unresponsive maintainer. The situation is compounded by the fact that runZero used an AI-assisted fuzzing pipeline to discover the flaws, meaning the barrier to exploitation is low, while downstream vendors face a potentially years-long patching process with no coordinated disclosure channel in place.

8 Jul 2026