IoT & Hardware

Hardware / Firmware Exposure

Information Disclosure

UART port of the Wi-Fi module controller is open to access

This vulnerability allows an attacker with physical access to the device to fully extract the firmware and internal memory contents.

4.6
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS96
PUBLISHED
2026-01-16
CVE IDs
CVE-2025-67399
VENDORS
Airth
PUBLIC EXPLOIT
None indexed
CWE
CWE-200
PRODUCT
AIRTH Smart Home AQI Monitor
CVSS VECTOR
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

The AIRTH Smart Home AQI Monitor uses a CB3S Bluetooth SoC based on the BK7231N chipset with Software version number: 2.1.17. By physically accessing the device and identifying the SOC, the exposed UART debug/programming pins were located using the publicly available datasheet. Direct connection to these pins via a USB-to-TTL converter and vendor-provided tools allowed unrestricted read access to the chip's memory. As a result, the complete firmware could be extracted without authentication or security checks. This issue is caused by missing hardware-level protections such as disabled debug interfaces, read-out protection, or secure boot, enabling unauthorized firmware and memory access through the UART interface.

Vulnerability details

Vulnerability details

CVE-2025-67399
CWE-200
Medium | 4.6

The AIRTH Smart Home AQI Monitor uses a CB3S Bluetooth SoC based on the BK7231N chipset with Software version number: 2.1.17.

Auth:
None (physical access)
Impact:
Sensitive data disclosure
Impact

What an attacker can do

This vulnerability allows an attacker with physical access to the device to fully extract the firmware and internal memory contents. As a result: · Firmware Intellectual Property Exposure: Proprietary firmware, algorithms and implementation details can be copied, reverse engineered or reused. · Credential and Key Disclosure: Sensitive data potentially stored in firmware or memory (such as Wi-Fi credentials, encryption keys, or API tokens) may be exposed. · Device Cloning and Counterfeiting: Extracted firmware can be flashed onto other hardware, enabling unauthorized device replication. · Firmware Modification and Malicious Reprogramming: Attackers could modify the firmware to introduce malicious functionality, persistent backdoors, or altered device behaviour. · Loss of User Privacy: Modified firmware could silently collect or transmit sensor data or network information without user consent. While exploitation requires physical access, the absence of basic hardware security protections significantly lower the barrier for firmware compromise and poses a serious risk to device security and intellectual property.

DISCLOSURE

Disclosure timeline

2025-09-26 Reported to vendor

2025-12-05 Reported to MITRE

2026-01-03 CVE ID Reserved

2026-01-14 CVE Published

Credits

Rupesh B. Surve – Payatu Security Consulting Pvt. Ltd.