漏洞标题
通过串行接口访问引导程序和壳命令界面
漏洞描述信息
通过物理接触Wattsense Bridge设备的PCB,可以访问其串行接口。连接到该接口后,可以访问引导加载程序,并出现Linux登录提示。通过访问引导加载程序,可以获得设备的root shell权限。此问题已在较新固件版本BSP >= 6.4.1中修复。
CVSS信息
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
认证机制不恰当
漏洞标题
Access to Bootloader and Shell Over Serial Interface
漏洞描述信息
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.
CVSS信息
N/A
漏洞类别
N/A