CVE-2025-26409
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.33%
- CWE
- CWE-1299, CWE-1191
- Published
- 2025-02-11
- Last modified
- 2026-03-13
Affected products
- Wattsense Wattsense Bridge
Weakness type
Related vulnerabilities
- CVE-2025-35998 — Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist...
- CVE-2025-41697 — Shell access to UART Console
- CVE-2025-1073 — Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical...
- CVE-2024-47944 — Missing Protection Mechanism for Alternate Hardware Interface
- CVE-2024-39723 — IBM FlashSystem denial of service
- CVE-2023-29063 — Lack of DMA Access Protections
- CVE-2023-29060 — Lack of USB Whitelisting
- CVE-2022-43557 — BD BodyGuard™ Pumps – RS-232 Interface Vulnerability