Weak Hard-coded Credentials
Vulnerability Description
The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-26410
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Constantin Schieber-Knöbl | SEC Consult Vulnerability Lab
- Stefan Schweighofer | SEC Consult Vulnerability Lab
- Steffen Robertz | SEC Consult Vulnerability Lab
References
Affected Vendor
Wattsense
View all reports →