First published: Tue Feb 11 2025(Updated: )
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.
Credit: 551230f0-3615-47bd-b7cc-93e92e730bbf
Affected Software | Affected Version | How to fix |
---|---|---|
Wattsense Bridge | >6.4.1 |
This issue is fixed in recent firmware versions BSP >= 6.4.1.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26409 is considered a high severity vulnerability due to the potential for unauthorized root access to the device.
To mitigate CVE-2025-26409, restrict physical access to Wattsense Bridge devices to prevent exploitation of the serial interface.
CVE-2025-26409 specifically affects Wattsense Bridge devices running version 6.4.1 or earlier.
CVE-2025-26409 allows an attacker with physical access to gain root access, potentially compromising the integrity and confidentiality of the device.
No, CVE-2025-26409 requires physical access to the Wattsense Bridge device to exploit the vulnerability.