The Nintendo Talking Flower firmware does not check the size of the language index table when loading it from SPI flash into RAM, allowing me to corrupt the stack, execute arbitrary code, and dump the protected STM32 firmware🤣
(SHA1 51ec2ee3bbc12772cd4abed1bf2d26b02e541e14)
about 1 month ago