PT-2025-6175 · Wattsense · Wattsense Bridge
Constantin Schieber-Knöbl
+2
·
Published
2025-02-11
·
Updated
2025-02-16
·
CVE-2025-26411
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Wattsense Bridge versions prior to 6.1.0
Description:
An authenticated attacker can use the Plugin Manager of the web interface to upload malicious Python files, enabling remote root access to the device. The attacker needs a valid user account on the Wattsense web interface to conduct this attack.
Recommendations:
For versions prior to 6.1.0, update to a firmware version BSP >= 6.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the Plugin Manager or disabling the upload of Python files until the update is applied.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wattsense Bridge