Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhwm-q72q-9mg9

Опубликовано: 07 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.

AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.

EPSS

Процентиль: 13%
0.00044
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-770

Связанные уязвимости

nvd
около 1 месяца назад

AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.

EPSS

Процентиль: 13%
0.00044
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-770