AZIOT 1 Node Smart Switch Information Disclosure Vulnerability via UART Debug Interface

Vulnerability

A vulnerability allowing information disclosure exists in the AZIOT 1 Node Smart Switch (16amp) with WiFi and Bluetooth capability, running software version 1.1.9. The issue arises from improper access control on the UART debug interface, which allows an attacker with physical access to connect to the UART interface and retrieve sensitive information from the serial console without authentication.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, such as WiFi credentials and encryption keys, through the UART interface.

Reproduction

The vulnerability can be reproduced by physically accessing the device and connecting to the UART interface. Once connected, the UART output can be monitored using a terminal program. The device's firmware can be dumped and analyzed with available tools, such as 'bk7231tools', which can extract sensitive data from the firmware, including keys and unencrypted logs.

Added: Apr 6, 2026, 6:32 PM
Updated: Apr 6, 2026, 6:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
5.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.