CVE 5.3 MEDIUM

AuntyFey Smart Combination Lock BLE Connection Flood DoS_CVE-2025-15474

5.3 / 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.

Basic Information

ID CVE-2025-15474
Source VulnCheck
Published Jan 7, 2026 at 04:33

Affected Product

Vendor AuntyFey
Product AuntyFey Smart Combination Lock
Affected Versions AuntyFey AuntyFey Smart Combination Lock 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.