A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution.
https://github.com/AzhariRamadhan/uboot-cve
https://gist.github.com/AzhariRamadhan/a5c9644861f46b1eadb1f2a15c7950fe