Home

Description

An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluetooth or RS-232 interface.

PUBLISHED Reserved 2025-04-10 | Published 2025-05-12 | Updated 2025-05-16 | Assigner CERTVDE




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Product status

Default status
unaffected

06.00.00 (semver) before 06.09.04
affected

Default status
unaffected

Any version before 01.02.00
affected

Default status
unaffected

Any version before 01-01.10.00
affected

Default status
unaffected

03.00.00 (semver) before 03.05.01
affected

Default status
unaffected

Any version before 01-01.09.00
affected

Default status
unaffected

Any version before 02-01.01.00
affected

Credits

Dennis Schaefer from ONEKEY GmbH finder

References

cert.vde.com/en/advisories/VDE-2025-026

cve.org (CVE-2025-3496)

nvd.nist.gov (CVE-2025-3496)

Download JSON