CVE-2025-41657CWE-207
AUMA: Incorrect delivery status of the Bluetooth configuration
Medium · published June 10, 2025
What it is
Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.
The record
Technical detail
- CVSS v3.1
- 4.3 · MEDIUM
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00185 · 8.1th percentile
- Weakness
- CWE-207 · Observable Behavioral Discrepancy With Equivalent Products
- Published
- 2025-06-10T10:46Z
EPSS history
Timeline