The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-4191 The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.
Fixes

Solution

The device is meant to be installed at a restricted access physical location according to the vendor and exploitation requires more attacker knowledge and higher physical access. The issue will be put in the backlog of the Wattsense team.


Workaround

No workaround given by the vendor.

History

Mon, 03 Nov 2025 22:30:00 +0000

Type Values Removed Values Added
References

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00022}

epss

{'score': 0.00025}


Sat, 22 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Tue, 18 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Tue, 11 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 09:30:00 +0000

Type Values Removed Values Added
Description The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.
Title Unprotected JTAG Interface
Weaknesses CWE-1191
References

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-11-03T21:12:50.335Z

Reserved: 2025-02-10T07:48:38.352Z

Link: CVE-2025-26408

cve-icon Vulnrichment

Updated: 2025-11-03T21:12:50.335Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-11T10:15:09.617

Modified: 2025-11-03T22:18:41.163

Link: CVE-2025-26408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.