CVE-2026-36742 Details
Description
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected (hidden/debug mode).
A vulnerability exists in the Hiseeu C90 firmware version 5.7.15, related to insecure permissions that expose the UART bootloader. This bootloader becomes accessible when the battery is disconnected, putting the device in a hidden debug mode. An attacker with physical access can connect to the UART interface, interrupt the boot process, and gain unrestricted access to low-level bootloader functions. Such access could lead to firmware extraction, arbitrary code execution, recovery of credentials, and complete compromise of the device.
The vendor should disable UART debug functionality in production devices, require authentication for bootloader access, remove hidden debug modes from release firmware, restrict low-level memory operations, implement secure boot protections, lock bootloader functionality in production hardware, and add tamper-resistant hardware protections.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36742 | CISA-ADP | ExploitRemedyTechnical DescriptionVendor |
| https://github.com/N0tMilk/vulnerability-research | [email protected] | Vendor |
| https://github.com/N0tMilk/vulnerability-research/tree/main/IoT/CVE-2026-36742 | [email protected] | ExploitRemedyTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Hiseeu C90 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |
Volerion