CVE-2025-26411 Details
Description
An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct this attack. This issue is fixed in recent firmware versions BSP >= 6.1.0.
A vulnerability exists in the Wattsense Bridge devices that allows authenticated attackers to upload harmful Python files through the Plugin Manager in the web interface. This action can lead to remote root access on the device. The vulnerability is present in Wattsense Bridge firmware versions prior to 6.1.0. To exploit this vulnerability, an attacker must have a valid user account on the Wattsense web interface and access to a bridge device that is connected to the internet.
Users are advised to update to Wattsense Bridge firmware version 6.1.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 11, 2025CISA-ADP
Assessed Feb 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://r.sec-consult.com/wattsense | SEC Consult Vulnerability Lab | BundleRemedyTechnical Analysis |
| https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes | SEC Consult Vulnerability Lab | Release NotesVendor |
| http://seclists.org/fulldisclosure/2025/Feb/9 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| Wattsense Bridge | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Mar 14, 2025 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 11, 2025 | CVE Modified | CISA-ADP |
| Feb 11, 2025 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion