CVE-2025-10457: Zephyrproject Zephyr

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. Instead, it relies solely on identifier matching.

Affected products

Published 2025-09-19. Last modified 2026-06-17.