CVE-2025-26409

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.
Configurations

No configuration.

History

03 Nov 2025, 22:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Feb/9 -

Information

Published : 2025-02-11 10:15

Updated : 2025-11-03 22:18


NVD link : CVE-2025-26409

Mitre link : CVE-2025-26409

CVE.ORG link : CVE-2025-26409


JSON object : View

Products Affected

No product.

CWE
CWE-1191

On-Chip Debug and Test Interface With Improper Access Control

CWE-1299

Missing Protection Mechanism for Alternate Hardware Interface