CVE-2025-10457
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-19

Last updated on: 2025-10-29

Assigner: Zephyr Project

Description
The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-19
Last Modified
2025-10-29
Generated
2026-06-16
AI Q&A
2025-09-19
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr to 4.1.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-358 The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability occurs because the function that handles Bluetooth Low Energy (BLE) connection responses does not check if a response is actually expected, meaning it does not verify if the device initiated a connection request. Instead, it only checks if the identifier matches, which can lead to improper handling of connection responses.

Impact Analysis

The vulnerability can lead to denial of service or disruption of BLE connections since the function may accept unexpected connection responses, potentially causing instability or interruption in BLE communication.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-10457. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart