PT-2025-54287 · Unknown · Serial Device Servers
Published
2025-12-31
·
Updated
2025-12-31
·
CVE-2025-15017
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
serial device servers (affected versions not specified)
Description
A flaw exists in serial device servers where active debug code is enabled in the UART interface. An attacker with physical access can connect to the UART interface and gain unauthorized access to internal debug functionality without authentication or user interaction. This allows an attacker to execute privileged operations and access sensitive system resources, impacting the confidentiality, integrity, and availability of the device. There is no identified security impact to external or dependent systems. Exploitation is considered low complexity.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serial Device Servers