CVE-2026-14297CWE-787

The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.

High · published September 7, 2026

CVSS v4.0
8.7
EPSS
In the wild
Unconfirmed
What it is

A buffer overflow in the Bluetooth Continuous Glucose

Monitoring Service (CGMS) Record Access Control Point (RACP) write handler

allows an authenticated BLE peer to overflow a 20-byte static buffer into

adjacent BSS memory. The exploitable impact cannot be predetermined - it

is entirely dependent on the linker-assigned BSS layout of the specific

firmware build, which may vary.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-787 · Out-of-bounds Write
Published
2026-09-07T08:07Z
Timeline
  • 07 SEP 08:07Z
    The Continuous Glucose Monitoring Service's Record Access Control Point (RACP) write handler `memcpy`s the entire attacker-supplied ATT write value into a fixed 20-byte BSS buffer.
    cvelistv5