CVE-2025-12890: Zephyrproject-Rtos Zephyr
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the chM 0x7CFFFFFFFF triggers a crash. The peripheral will not be connectable after it.
Affected products
- Zephyrproject-Rtos Zephyr
Published 2025-11-07. Last modified 2026-10-07.