CVE-2025-36939
Received Received - Intake

Denial of Service in OpenThread MLE Packet Handling

Vulnerability report for CVE-2025-36939, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Google Devices

Description

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openthread openthread *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves multiple issues in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network can send specially crafted packets to cause a denial of service. The issues include assertion failures that can be triggered and a stack-based buffer overflow.

Detection Guidance

Detection requires monitoring Thread network traffic for malformed MLE packets. Use packet capture tools like Wireshark with Thread protocol support to inspect MLE packets for anomalies. Check OpenThread logs for assertion failures or crashes. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could allow an attacker to disrupt the operation of a Thread network by causing devices to crash or become unresponsive. This could lead to loss of network connectivity and services dependent on the network.

Compliance Impact

The vulnerability causes denial of service and potential data disruption on Thread networks, which could impact systems handling sensitive data. However, the provided CVE details do not specify direct compliance impacts on GDPR or HIPAA.

Mitigation Strategies

Update OpenThread to the latest patched version immediately. Isolate affected Thread networks from untrusted devices. Monitor network traffic for unusual patterns. Apply network segmentation to limit exposure. Disable MLE packet processing if not critical.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-36939. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart