Executive brief
The AZIOT 1 Node Smart Switch, a device used for remote control of electrical appliances, contains a security flaw in its hardware interface. An individual with physical access to the device can connect to its internal diagnostic port to bypass security controls. This allows them to extract sensitive information, such as Wi-Fi credentials, which could lead to further unauthorized access to the owner's home or business network.
Technical details
An information disclosure vulnerability (CWE-200) exists in the AZIOT 1 Node Smart Switch (16amp) running software version 1.1.9. The vulnerability stems from improper access control on the UART debug interface of the Beken chipset. An attacker with physical access to the device's internal pins can connect to the serial console without authentication. By interacting with this interface, an attacker can dump the device's firmware and storage, potentially recovering sensitive information such as SSIDs and Wi-Fi passwords (PSK) stored in plaintext or easily reversible formats.
Affected products
- AZIOT 1 Node Smart Switch (16amp) - WiFi/Bluetooth Enabled 1.1.9
Timeline
- 2026-04-06: disclosed
- 2026-04-06: advisory