In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.
https://www.nccgroup.com/research-blog/there-s-another-hole-in-your-soc-unisoc-rom-vulnerabilities/