CVE-2026-65058CWE-358

Trezor Safe improper security check in on-device display

Medium · published July 21, 2026

CVSS v4.0
5.9
EPSS
0%
Percentile
33.1
In the wild
Unconfirmed
What it is

Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c.

The record
Technical detail
CVSS v4.0
5.9 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00398 · 33.1th percentile
Weakness
CWE-358 · Improperly Implemented Security Check for Standard
Published
2026-07-21T20:13Z
EPSS history
Timeline
  • 21 JUL 20:13Z
    Trezor Safe improper security check in on-device display
    cvelistv5