Hiseeu C90 Insecure Permissions Vulnerability Allowing Full Device Compromise

Vulnerability

A vulnerability exists in the Hiseeu C90 firmware version 5.7.15, related to insecure permissions that expose the UART bootloader. This bootloader becomes accessible when the battery is disconnected, putting the device in a hidden debug mode. An attacker with physical access can connect to the UART interface, interrupt the boot process, and gain unrestricted access to low-level bootloader functions. Such access could lead to firmware extraction, arbitrary code execution, recovery of credentials, and complete compromise of the device.

Impact

Exploitation of this vulnerability allows for arbitrary code execution and full compromise of the device.

Reproduction

To reproduce this vulnerability, physically access the Hiseeu C90 device and open its enclosure. Disconnect the battery and power the device externally. Once the device is powered, the UART pins on the internal PCB can be accessed. Connect a UART adapter set to 115200 baud to the exposed pins. This connection will allow interruption of the boot process and access to the unauthenticated bootloader console over UART.

Remediation

The vendor should disable UART debug functionality in production devices, require authentication for bootloader access, remove hidden debug modes from release firmware, restrict low-level memory operations, implement secure boot protections, lock bootloader functionality in production hardware, and add tamper-resistant hardware protections.

Added: May 13, 2026, 8:05 PM
Updated: May 13, 2026, 8:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
0.0
relevance
8.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.