CyberRota Analysis
AI-GeneratedBluetooth Mesh SDK versions 6.1.4 and earlier are vulnerable to out-of-bounds writes caused by malformed extended advertisements, which can lead to stack corruption and potential remote code execution. This vulnerability requires that the malicious messages originate from a device already part of the network, affecting only provisioners that support extended advertisements. Organizations using these SDK versions should prioritize immediate patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.