Executive brief
A security vulnerability exists in the AIRTH Smart Home AQI Monitor, a device used to track indoor air quality. An attacker with physical access to the device can connect to internal hardware components to extract sensitive information. This could lead to the exposure of private data or device credentials, potentially compromising the user's privacy or home network security.
Technical details
The AIRTH Smart Home AQI Monitor Bootloader (v1.005) fails to secure the Universal Asynchronous Receiver-Transmitter (UART) interface on the BK7231N Wi-Fi and BLE controller. A physically proximate attacker can interface with these exposed pins to access the bootloader environment or system logs. This access allows for the unauthorized extraction of sensitive information from the device's memory or storage. The attack requires physical disassembly or access to the device's internal circuitry, but no prior authentication is required.
Affected products
- AIRTH Smart Home AQI Monitor Bootloader 1.005
Timeline
- 2026-01-14: advisory: Initial NVD publication date
- 2026-01-14: disclosed: Public disclosure of the vulnerability details via GitHub repository