CVE-2025-67399

An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access
Configurations

Configuration 1 (hide)

cpe:2.3:a:airth:smart_home_aqi_monitor_bootloader:1.005:*:*:*:*:*:*:*

History

05 Jul 2026, 02:17

Type Values Removed Values Added
References
  • {'url': 'http://airth.com', 'tags': ['Permissions Required'], 'source': 'cve@mitre.org'}

17 Jun 2026, 09:57

Type Values Removed Values Added
Summary
  • (es) Un problema en el Bootloader v.1.005 de AIRTH SMART HOME AQI MONITOR permite a un atacante físicamente próximo obtener información sensible a través del puerto UART del controlador BK7231N (módulo Wi-Fi y BLE), que en el dispositivo está abierto al acceso.

12 Feb 2026, 17:54

Type Values Removed Values Added
First Time Airth smart Home Aqi Monitor Bootloader
Airth
References () http://airth.com - () http://airth.com - Permissions Required
References () https://github.com/rupeshsurve04/CVE-2025-67399/blob/main/AIRTH_SMART_HOME_AQI_MONITOR_CVE-2025-67399.pdf - () https://github.com/rupeshsurve04/CVE-2025-67399/blob/main/AIRTH_SMART_HOME_AQI_MONITOR_CVE-2025-67399.pdf - Third Party Advisory
CPE cpe:2.3:a:airth:smart_home_aqi_monitor_bootloader:1.005:*:*:*:*:*:*:*

14 Jan 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
CWE CWE-200

14 Jan 2026, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 16:15

Updated : 2026-07-05 02:17


NVD link : CVE-2025-67399

Mitre link : CVE-2025-67399

CVE.ORG link : CVE-2025-67399


JSON object : View

Products Affected

airth

  • smart_home_aqi_monitor_bootloader
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor