IoT & Hardware
Hardware / Firmware Exposure
Information Disclosure
Exposure of Stored Credentials via Open UART Logs and Firmware Dump
This vulnerability allows an attacker with physical access to the device to fully extract the firmware and internal memory contents.
.png)
Overview
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access to the device can connect to the exposed UART interface and read sensitive information and dump or change the firmware from the serial console without authentication due to missing or improper access control.
Vulnerability details
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface.
What an attacker can do
This vulnerability allows an attacker with physical access to the device to fully extract the firmware and internal memory contents. As a result: Firmware Intellectual Property Exposure: Proprietary firmware, algorithms and implementation details can be copied, reverse engineered or reused. Credential and Key Disclosure: Sensitive data potentially stored in firmware or memory (such as Wi-Fi credentials, encryption keys, or API tokens) may be exposed. Device Cloning and Counterfeiting: Extracted firmware can be flashed onto other hardware, enabling unauthorized device replication. Firmware Modification and Malicious Reprogramming: Attackers could modify the firmware to introduce malicious functionality, persistent backdoors, or altered device behavior.
Disclosure timeline
2026-01-14 Reported to vendor
2026-02-03 Reported to MITRE
2026-03-23 CVE ID Reserved
2026-04-06 CVE Published
References
Credits
Mohammad Natiq Khan – Payatu Security Consulting Pvt. Ltd.
















