CVE-2026-5706CWE-130

CVE-2026-5706

published August 28, 2026

CVSS
8.9
EPSS
0%
Percentile
18.5
In the wild
Unconfirmed
What it is

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.

The record
Technical detail
CVSS
8.9 · NONE
CVSS v4.0
8.9 · CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H
EPSS
0.00266 · 18.5th percentile
Weakness
CWE-130 · Improper Handling of Length Parameter Inconsistency
Published
2026-08-28T04:18Z
References (2)
EPSS history
Timeline
  • 27 AUG 22:13Z
    Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements
    cvelistv5