Junglewise Threat Intelligence

CVE-2026-36742: Hiseeu C90 insecure permissions in UART bootloader

CVE-2026-36742 · Severity: info · CVSS 0 · Published 2026-05-13

Executive brief

The Hiseeu C90 security camera contains a debug interface that becomes accessible when the device's battery is disconnected. An attacker with physical access to the camera can use this interface to bypass security controls, potentially allowing them to steal stored credentials, extract the camera's software, or take complete control of the device. This could lead to unauthorized surveillance or the use of the camera as a foothold to attack other devices on the same network.

Technical details

Hiseeu C90 firmware version 5.7.15 contains an unauthenticated UART bootloader interface accessible via physical pins on the internal PCB. When the battery is disconnected and the device is powered externally, it enters a hidden debug mode that exposes a bootloader console at 115200 baud. This console provides low-level commands including memory read/write (r/w), XModem/YModem firmware uploads (x/y), and arbitrary code execution (g/e). An attacker with physical access can interrupt the boot process to dump firmware, recover cloud/P2P credentials, or modify the system persistently. No authentication is required to access these primitives once the hardware is accessed.

Affected products

  • Hiseeu C90 5.7.15

Timeline

  • 2026-05-13: disclosed: Initial disclosure via MITRE and researcher repository
  • 2026-05-13: advisory: NVD entry created

References