In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security restrictions on firmware operations. Using these flaws, malicious firmware code can elevate privileges, permanently make the device inoperable or overwrite the trusted bootloader code to compromise the hardware wallet across reboots or storage wipes.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30330.json",
"cna_assigner": "mitre"
}"2026-07-22T02:24:55Z"
[
{
"id": "CVE-2022-30330-433a3d61",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 477.0,
"function_hash": "294123191815334012997121978248847040035"
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"function": "check_bootloader",
"file": "tools/firmware/keepkey_main.c"
}
},
{
"id": "CVE-2022-30330-470f76da",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 332.0,
"function_hash": "292003018493310952547530825061636564952"
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"function": "unknown_bootloader",
"file": "tools/blupdater/main.c"
}
},
{
"id": "CVE-2022-30330-4bd28af0",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1609.0,
"function_hash": "116830319557477195367067723787426946390"
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"function": "get_bootloaderKind",
"file": "lib/board/check_bootloader.c"
}
},
{
"id": "CVE-2022-30330-6362b26e",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"44611891952244110137375183281031675443",
"285428054455441636551810293750827266429",
"238945426805892685539688189408648265507",
"275047964691103085612777863797520235928"
]
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"file": "tools/blupdater/main.c"
}
},
{
"id": "CVE-2022-30330-9d9d19a1",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"44611891952244110137375183281031675443",
"312802404481325664305582578438073565422",
"206495168246894855798233768397014041279",
"191737711206465611254906142848055955884"
]
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"file": "lib/board/keepkey_flash.c"
}
},
{
"id": "CVE-2022-30330-9e728fbb",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"100486001065654198556583097111432050866",
"324704991906621117028231293143300007857",
"289206258741950998795293187606917836369",
"160740731416919829693198335420396944711",
"83245503881923196889459922263061078844",
"275628103680180835140189982885236430416",
"233408394917263064509023569219007779968",
"225687162349266686323325860628937650243",
"314150643277007710007947557131622118644"
]
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"file": "tools/firmware/keepkey_main.c"
}
},
{
"id": "CVE-2022-30330-a912fc20",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 777.0,
"function_hash": "107269180900077278528261167648131053723"
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"function": "flash_programModel",
"file": "lib/board/keepkey_flash.c"
}
},
{
"id": "CVE-2022-30330-cf8739b9",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"188621247341080256233441335575939154225",
"259373863761664844412612366561944438166",
"282212781327136127667729445878463542616",
"309067033668450140011323100507921825959",
"303948376131732361393495404646008295580",
"183883622822530225792083245797793737027",
"336312453251804640968890216457717990935"
]
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"file": "lib/board/check_bootloader.c"
}
},
{
"id": "CVE-2022-30330-eb733228",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"166170415739160617500600119944133374065",
"211746958265260322046587769297945740896",
"263317472117347925626166367616046917449",
"293323260150058115567354305275795986022",
"159520476636501467449652118052637211635",
"251048974044874976237070641682657099010",
"210163504328892399685724825243540497966",
"157785186458539734999334610881965610621"
]
},
"source": "https://github.com/keepkey/keepkey-firmware/commit/0591b1ce9f604c19a1b90bbf743f8f7606ae8722",
"target": {
"file": "include/keepkey/board/check_bootloader.h"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-30330.json"