Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-67399 | Kitploit
Tools/GitHubGitHub/rupeshsurve04/cve-2025-67399
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationHardware HackingHardware SecurityFirmware Analysis
GitHubrupeshsurve04/cve-2025-67399

CVE-2025-67399

View Repository
7 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-67399

Vulnerability Summary

The AIRTH Smart Home AQI Monitor uses a CB3S Bluetooth SoC based on the BK7231N chipset with Software version number: 2.1.17. By physically accessing the device and identifying the SoC, the exposed UART debug/programming pins were located using the publicly available datasheet. Direct connection to these pins via a USB-to-TTL converter and vendor-provided tools allowed unrestricted read access to the chip’s memory. As a result, the complete firmware could be extracted without authentication or security checks. This issue is caused by missing hardware-level protections such as disabled debug interfaces, read-out protection, or secure boot, enabling unauthorized firmware and memory access through the UART interface.

Overall CVSS Score: 6.8

CVSS 3.1 Vector: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Download Tool