SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-36939

CRITICAL · CVSS 10 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenThread is vulnerable to multiple critical issues in its handling of MLE packets, allowing an authenticated attacker on the same Thread network to exploit specially crafted packets. This could lead to denial of service through assertion failures and stack-based buffer overflows. Organizations utilizing OpenThread in their network infrastructure should prioritize addressing this vulnerability to mitigate potential disruptions.

CVE
CVE-2025-36939
Severity
CRITICAL
CVSS
10
EPSS
0.23%

Original NVD Description

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.