CVE-2025-36939: Google Nest Wifi Point Firmware

Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.

Affected products

  • Google Nest Wifi Point Firmware: version 3.78.518349 only
  • Google Nest Wifi Pro Firmware: version 3.78.518349 only
  • Google Nest Wifi Router Firmware: version 3.78.518349 only

Published 2026-08-24. Last modified 2026-10-07.