蓝牙连续葡萄糖监测服务(CGMS)记录访问控制点(RACP)的写入处理器中存在缓冲区溢出漏洞。经过认证的蓝牙低功耗(BLE)对等方可以将 20 字节的静态缓冲区溢出到相邻的 BSS 内存中。该漏洞的可利用影响无法预先确定——它完全取决于特定固件构建中由链接器分配的 BSS 内存布局,而这可能各不相同。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nordic Semiconductor ASA | nRF Connect SDK | 2.2.0 ~ 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14296 | 7.5 HIGH | nRF54H20: MCUBoot can be tricked to executing unauthenticated code |
| CVE-2026-18796 | 6.8 MEDIUM | QSPI flash encryption side-channel leakage |
No comments yet