Vulnerability Description
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://r.sec-consult.com/wattsense
- https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes
- http://seclists.org/fulldisclosure/2025/Feb/9
FAQ
What is CVE-2025-26409?
CVE-2025-26409 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt...
How severe is CVE-2025-26409?
CVE-2025-26409 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-26409?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.