CVE-2025-10457: Zephyrproject Zephyr
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.
Affected products
- Zephyrproject Zephyr: up to and including 4.1.0
Published 2025-09-19. Last modified 2026-06-17.