PT-2025-6174 · Wattsense · Wattsense Bridge
Constantin Schieber-Knöbl
+2
·
Published
2025-02-11
·
Updated
2025-02-16
·
CVE-2025-26410
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Wattsense Bridge versions prior to 6.4.1
Description:
The firmware of all Wattsense Bridge devices contains the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface.
Recommendations:
For Wattsense Bridge versions prior to 6.4.1, update the firmware to version 6.4.1 or later to remove the backdoor user and hard-coded credentials.
As a temporary workaround, consider restricting access to the serial interface to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wattsense Bridge