{
  "node_id": "mitre-capec-capec-682-exploitation-of-firmware-or-rom-code-with-unpatchable",
  "title": "MITRE CAPEC-682: Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities (Standard Attack Pattern - High Severity)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-682 (Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary may exploit vulnerable code (i.e., firmware or ROM) that is unpatchable. Unpatchable devices exist due to manufacturers intentionally or inadvertently designing devices incapable of updating their software. Additionally, with updatable devices, the manufacturer may decide not to support the device and stop making updates to their software. Likelihood of attack: Medium. Typical severity: High. Maps to weaknesses CWE-1277, CWE-1310.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2"
  ],
  "primary_citations_count": 8
}