PT-2025-6175 · Wattsense · Wattsense Bridge

Constantin Schieber-Knöbl

+2

·

Published

2025-02-11

·

Updated

2025-02-16

·

CVE-2025-26411

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Wattsense Bridge versions prior to 6.1.0
Description: An authenticated attacker can use the Plugin Manager of the web interface to upload malicious Python files, enabling remote root access to the device. The attacker needs a valid user account on the Wattsense web interface to conduct this attack.
Recommendations: For versions prior to 6.1.0, update to a firmware version BSP >= 6.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the Plugin Manager or disabling the upload of Python files until the update is applied.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-26411

Affected Products

Wattsense Bridge