Skip to main content

CWE archive

CWE-1191 CVEs

Programmatic archive

22 CVEs tagged with CWE-11911 Critical, 7 High, 12 Medium, 2 Low, 0 Unrated.

CVE-2026-8989

Published Jul 21, 2026

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical ac…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8988

Published Jul 21, 2026

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An atta…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-52533

Published Feb 12, 2026

Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.

CVSS 8.7 · High

CVE-2024-36319

Published Feb 12, 2026

Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW…

CVSS 6.3 · Medium

CVE-2025-15083

Published Dec 25, 2025

A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation can lead to on-chi…

CVSS 0.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-36755

Published Dec 12, 2025

The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that…

CVSS 2.4 · Low

CVE-2025-9709

Published Sep 5, 2025

On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attack…

CVSS 8.6 · High

CVE-2025-7213

Published Jul 9, 2025

A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to…

CVSS 4.5 · Medium

CVE-2025-26409

Published Feb 11, 2025

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as…

CVSS 6.8 · Medium

CVE-2025-26408

Published Feb 11, 2025

The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enab…

CVSS 6.1 · Medium

CVE-2024-48970

Published Nov 14, 2024

The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debuggi…

CVSS 9.3 · Critical

CVE-2024-41692

Published Jul 26, 2024

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physi…

CVSS 8.6 · High

CVE-2024-4231

Published May 14, 2024

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without p…

CVSS 6.8 · Medium

CVE-2023-32666

Published Mar 14, 2024

On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged use…

CVSS 7.2 · High

CVE-2020-9285

Published Oct 20, 2022

Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the m…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1