CVE-2025-10457Improperly Implemented Security Check for Standard in Zephyr

Severity
8.1HIGHNVD
CNA4.3
EPSS
0.0%
top 87.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19

Description

The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5zephyrproject-rtos/zephyr*4.1.0

🔴Vulnerability Details

1
CVEList
Bluetooth: Out-Of-Context le_conn_rsp Handling2025-09-19
CVE-2025-10457 — Zephyr vulnerability | cvebase