Medium severity6.6NVD Advisory· Published May 7, 2022· Updated Jun 17, 2026
CVE-2022-30330
CVE-2022-30330
Description
In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operations. Using these flaws, malicious firmware code can elevate privileges, permanently make the device inoperable or overwrite the trusted bootloader code to compromise the hardware wallet across reboots or storage wipes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:o:keepkey:keepkey_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:keepkey:keepkey_firmware:*:*:*:*:*:*:*:*range: <7.3.2
- (no CPE)range: <7.3.2
- KeepKey/KeepKey firmwaredescription
Patches
Vulnerability mechanics
References
3- github.com/keepkey/keepkey-firmware/commit/447c1f038a31378ab9589965c098467d9ea6ccccnvdPatchThird Party Advisory
- blog.inhq.net/posts/keepkey-CVE-2022-30330/nvdExploitPatchThird Party Advisory
- github.com/keepkey/keepkey-firmware/releases/tag/v7.3.2nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.