Junglewise Threat Intelligence

CVE-2025-67399: AIRTH Smart Home AQI Monitor information disclosure via UART port

CVE-2025-67399 · Severity: medium · CVSS 4.6 · Published 2026-01-14

Executive brief

A security vulnerability exists in the AIRTH Smart Home AQI Monitor, a device used to track indoor air quality. An attacker with physical access to the device can connect to internal hardware components to extract sensitive information. This could lead to the exposure of private data or device credentials, potentially compromising the user's privacy or home network security.

Technical details

The AIRTH Smart Home AQI Monitor Bootloader (v1.005) fails to secure the Universal Asynchronous Receiver-Transmitter (UART) interface on the BK7231N Wi-Fi and BLE controller. A physically proximate attacker can interface with these exposed pins to access the bootloader environment or system logs. This access allows for the unauthorized extraction of sensitive information from the device's memory or storage. The attack requires physical disassembly or access to the device's internal circuitry, but no prior authentication is required.

Affected products

  • AIRTH Smart Home AQI Monitor Bootloader 1.005

Timeline

  • 2026-01-14: advisory: Initial NVD publication date
  • 2026-01-14: disclosed: Public disclosure of the vulnerability details via GitHub repository

References