8.1
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Authentication Bypass by Spoofing vulnerability in Apache NimBLE.
Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor.
This issue affects Apache NimBLE: through 1.8.0.
Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor.
This issue affects Apache NimBLE: through 1.8.0.
Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Basic Information
ID
CVE-2025-62235
Source
apache
Published
Jan 10, 2026 at 09:42
Modified
Jan 12, 2026 at 16:45
Affected Product
Vendor
Apache Software Foundation
Product
Apache Mynewt NimBLE
Affected Versions
Apache Software Foundation Apache Mynewt NimBLE 0