CVE Vulnerabilities

CVE-2025-10457

Improperly Implemented Security Check for Standard

Published: Sep 19, 2025 | Modified: Oct 29, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.

Weakness

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

Affected Software

Name Vendor Start Version End Version
Zephyr Zephyrproject * 4.1.0 (including)

References