Access to Bootloader and Shell Over Serial Interface
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
In short
Wattsense Bridge devices have a serial port on their circuit board that allows anyone with physical access to log in as root or control the bootloader, potentially taking over the device.
Technical detail
Physical access to the PCB serial interface enables bootloader access and unauthenticated root shell login without credentials. An attacker with physical proximity can exploit the unprotected serial port to modify firmware or execute arbitrary commands with elevated privileges.
Summary generated and translated by AI from the official description.
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Wattsense · Wattsense Bridge