# CVE-2025-26409

## Summary

- **CVE ID:** CVE-2025-26409
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-1299, CWE-1191
- **Published:** Feb 11, 2025
- **Last Modified:** Mar 13, 2026

## Description

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.

## Affected Products

- Wattsense — Wattsense Bridge (0)

## References

- [CNA](https://r.sec-consult.com/wattsense)
- [CNA](https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes)
- [CVE](http://seclists.org/fulldisclosure/2025/Feb/9)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.33%
- **EPSS Percentile:** 26.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._