PT-2025-6174 · Wattsense · Wattsense Bridge

Constantin Schieber-Knöbl

+2

·

Published

2025-02-11

·

Updated

2025-02-16

·

CVE-2025-26410

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wattsense Bridge versions prior to 6.4.1
Description: The firmware of all Wattsense Bridge devices contains the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface.
Recommendations: For Wattsense Bridge versions prior to 6.4.1, update the firmware to version 6.4.1 or later to remove the backdoor user and hard-coded credentials. As a temporary workaround, consider restricting access to the serial interface to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-26410

Affected Products

Wattsense Bridge