“All an attacker needs is just 30 seconds alone with the device to attach to the serial port, log in, deploy malware, and leave.”

A Worldline card terminal common in Switzerland gives a root shell on its serial port with no password. A hatch on the back exposes the debug connector without tripping the tamper protection. The firmware built in 2023 runs a 2010 Buildroot and a Linux 3.6 kernel. The card and PIN handling sits on a separate secure chip, which is the only reason this is not a disaster.