Zero Axis A.I CyberSecurity Scoring
Zero Axis
Company Information
Website:https://www.zero-axis.com
Employees number:16
Number of followers:1,872
NAICS:51122
Industry Type:Embedded Software Products
Homepage:zero-axis.com
Zero Axis Risk Score (AI oriented)
Between 700 and 749
Zero AxisEmbedded Software Products
Updated:
06/07/2026
06/07/2026
748/1000
Moderate
Ba
Zero Axis Global Score (TPRM)
xxxx
Zero AxisEmbedded Software Products
Score locked

Zero AxisModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
748
JUNE 2026
748
MAY 2026
748
APRIL 2026
748
MARCH 2026
750
Vulnerability
01 Mar 2026 • Zero Axis
STMicroelectronics, Zephyr Project, Espressif, ArduPilot and RT-Thread: Seven Bugs in FatFs Put IoT and Embedded Devices at Risk
Seven Critical Vulnerabilities in FatFs Expose IoT and Embedded Devices to Attacks
747
CRITICAL-3
ZERTHEESPSTMARD1783341911
Seven Critical Vulnerabilities in FatFs Expose IoT and Embedded Devices to Attacks
Cybersecurity firm runZero disclosed seven vulnerabilities in FatFs, a widely used open-source filesystem library for embedded and IoT devices, on July 6, 2026. The flaws, ranging from CVSS 4.6 (Medium) to 7.6 (High), can lead to memory corruption, crashes, data leaks, or remote code execution when devices process maliciously crafted storage media (e.g., USB drives, SD cards).
### Discovery and Impact
The vulnerabilities were uncovered during a 2026 re-audit of FatFs, which had previously undergone a 2017 security review with minimal findings. This time, researchers leveraged GitHub Copilot in auto mode to automate fuzzing and exploit validation, revealing issues that manual testing had missed. The flaws affect numerous platforms, including:
- Espressif ESP-IDF
- STMicroelectronics STM32Cube
- Zephyr RTOS
- MicroPython
- ArduPilot
- RT-Thread
- Mbed
- Samsung TizenRT
- SWUpdate
Downstream devices such as security cameras, voting machines, ATMs, drones, and industrial controllers are at risk, particularly those lacking modern memory protections like ASLR. Physical access to vulnerable devices could allow attackers to gain full control, while two flaws (CVE-2026-6682, CVE-2026-6683) also enable remote exploitation via firmware updates.
### Vulnerability Breakdown
1. CVE-2026-6682 (CVSS 7.6) – FAT32 integer overflow in `mount_volume()` leading to heap/stack corruption and potential code execution.
2. CVE-2026-6687 (CVSS 7.6) – exFAT label-length stack overflow causing memory corruption.
3. CVE-2026-6688 (CVSS 7.6) – Long filename overflow in downstream code, risking buffer overflows via `strcpy`/`sprintf`.
4. CVE-2026-6685 (CVSS 6.1) – Unsigned subtraction wrap in dirty-cache handling, risking silent data corruption.
5. CVE-2026-6683 (CVSS 4.6) – exFAT divide-by-zero in sync/write paths, causing crashes or bricking during firmware updates.
6. CVE-2026-6686 (CVSS 4.6) – Uninitialized cluster exposure, leaking stale deleted file data.
7. CVE-2026-6684 (CVSS 4.6) – GPT partition scan loop in pre-R0.16 versions, enabling boot-time denial-of-service.
### Patch Status and Challenges
FatFs is maintained by a single developer, who did not respond to disclosure attempts. JPCERT/CC was also unable to facilitate coordination. Only one flaw (CVE-2026-6684) has an upstream fix (in R0.16), but vendors must manually integrate it into their vendored copies. The lack of a responsive maintainer and widespread custom modifications by vendors complicate patching, mirroring delays seen in past disclosures like PixieFail (2024).
### Proof-of-Concept and Current Threat
runZero released proof-of-concept disk images, a test harness, and a QEMU-based exploit demo in a public repository. As of the disclosure date, no active attacks had been reported. However, the automated tooling used to find these flaws is now widely accessible, increasing the risk of future exploitation.
The vulnerabilities underscore the long-term risks of widely embedded, minimally maintained components in critical infrastructure and consumer devices.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
AUGUST 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Zero Axis ??
What was Zero Axis's A.I Rankiteo Cyber Score in June 2026 ??
What was Zero Axis's A.I Rankiteo Cyber Score in May 2026 ??
What was Zero Axis's A.I Rankiteo Cyber Score in April 2026 ??
What was Zero Axis's A.I Rankiteo Cyber Score in March 2026 ??
What was Zero Axis's A.I Rankiteo Cyber Score in February 2026 ??
What was Zero Axis's A.I Rankiteo Cyber Score in January 2026 ??
What was Zero Axis's A.I Rankiteo Cyber Score in December 2025 ??
What was Zero Axis's A.I Rankiteo Cyber Score in November 2025 ??
What was Zero Axis's A.I Rankiteo Cyber Score in October 2025 ??
What was Zero Axis's A.I Rankiteo Cyber Score in September 2025 ??
What was Zero Axis's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Zero Axis's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Zero Axis ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Zero Axis's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?