CVE-2018-16986: Ti Ble-Stack

High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow.

Affected products

  • Ti Ble-Stack: up to and including 2.2.1; version 3.0.0 only; up to and including 2.3.3

Published 2018-11-06. Last modified 2026-06-17.