CVE-2025-10457

Published Sep 19, 2025

Last updated 4 months ago

Overview

Description
The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.
Source
vulnerabilities@zephyrproject.org
NVD status
Analyzed
Products
zephyr

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity
HIGH

Weaknesses

vulnerabilities@zephyrproject.org
CWE-358

Social media

Hype score
Not currently trending

Configurations