Unauthorized Access through UART Port in Vulnerable Hardware
CVE-2025-41697

6.8MEDIUM

Key Information:

Vendor
CVE Published:
9 December 2025

What is CVE-2025-41697?

A significant security flaw exists in certain hardware configurations that expose an undocumented UART port on the PCB. This vulnerability allows an attacker to exploit this side-channel method to gain root access to the device. By utilizing credentials obtained from related vulnerabilities, such as those outlined in CVE-2025-41692, malicious actors can compromise the system, potentially leading to severe data breaches or control over the affected hardware. This highlights the importance of securing hardware interfaces in embedded systems.

Affected Version(s)

FL NAT 2008 0.0.0 < 3.50

FL NAT 2208 0.0.0 < 3.50

FL NAT 2304-2GC-2SFP 0.0.0 < 3.50

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube
.