CVE-2025-41697CWE-1299
Shell access to UART Console
Medium · published December 9, 2025
What it is
An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.
The record
Technical detail
- CVSS v3.1
- 6.8 · MEDIUM
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00235 · 14.3th percentile
- Weakness
- CWE-1299 · Missing Protection Mechanism for Alternate Hardware Interface
- Published
- 2025-12-09T08:12Z
EPSS history
Timeline