IoT & Hardware

Hardware / Firmware Exposure

Information Disclosure

Exposure of Stored Credentials via Open UART Logs and Firmware Dump

This vulnerability allows an attacker with physical access to the device to fully extract the firmware and internal memory contents.

4.6
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS99
PUBLISHED
2026-04-22
CVE IDs
CVE-2026-30613
VENDORS
AZIOT
PUBLIC EXPLOIT
None indexed
CWE
CWE-200
PRODUCT
Aziot 1Node Smart Switch (16amp)
CVSS VECTOR
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access to the device can connect to the exposed UART interface and read sensitive information and dump or change the firmware from the serial console without authentication due to missing or improper access control.

Vulnerability details

Vulnerability details

CVE-2026-30613
CWE-200
Medium | 4.6

An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface.

Auth:
None (physical access)
Impact:
Sensitive data disclosure
Impact

What an attacker can do

This vulnerability allows an attacker with physical access to the device to fully extract the firmware and internal memory contents. As a result: Firmware Intellectual Property Exposure: Proprietary firmware, algorithms and implementation details can be copied, reverse engineered or reused. Credential and Key Disclosure: Sensitive data potentially stored in firmware or memory (such as Wi-Fi credentials, encryption keys, or API tokens) may be exposed. Device Cloning and Counterfeiting: Extracted firmware can be flashed onto other hardware, enabling unauthorized device replication. Firmware Modification and Malicious Reprogramming: Attackers could modify the firmware to introduce malicious functionality, persistent backdoors, or altered device behavior.

DISCLOSURE

Disclosure timeline

2026-01-14 Reported to vendor

2026-02-03 Reported to MITRE

2026-03-23 CVE ID Reserved

2026-04-06 CVE Published

Credits

Mohammad Natiq Khan – Payatu Security Consulting Pvt. Ltd.