CVE-2025-26409: Wattsense Bridge
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.
Affected products
- Wattsense Wattsense Bridge: before 6.4.1 (fixed in 6.4.1)
Published 2025-02-11. Last modified 2026-06-17.