Wattsense Bridge JTAG Interface Access Vulnerability

Vulnerability

A vulnerability exists in Wattsense Bridge devices, allowing physical access to the JTAG interface on the PCB. This access enables full control over the device, including the ability to extract, modify, and debug the firmware. All known versions of the Wattsense Bridge are affected.

Impact

Exploitation of this vulnerability allows an attacker with physical access to the device to gain full control over it, including the ability to manipulate firmware and potentially install backdoors for remote access.

Reproduction

The JTAG interface can be accessed by soldering wires to specific pins on the PCB, including TMS, TCK, TDI, TDO, and TRST. After connecting these pins to a JTAG adapter, the OpenOCD debugging software can be used to read and modify the device's firmware.

Remediation

Wattsense has released a patch for this vulnerability in version 6.4.1 and later. Users are advised to update their devices to this version.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.