CVE-2025-41697CWE-1299

Shell access to UART Console

Medium · published December 9, 2025

CVSS v3.1
6.8
EPSS
0%
Percentile
14.3
In the wild
Unconfirmed
What it is

An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00235 · 14.3th percentile
Weakness
CWE-1299 · Missing Protection Mechanism for Alternate Hardware Interface
Published
2025-12-09T08:12Z
EPSS history
Timeline
  • 09 DEC 08:12Z
    Shell access to UART Console
    cvelistv5