CVE-2025-15645

Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause the device to enter an unrecoverable fault state during boot, resulting in permanent loss of operability.
Configurations

No configuration.

History

24 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Los dispositivos Ledger Nano X, Flex y Stax contienen una vulnerabilidad de denegación de servicio en el proceso de actualización del firmware del MCU debido a la falta de validación del parámetro reset_handler durante el flasheo del firmware. Un atacante puede proporcionar una dirección reset_handler manipulada que apunte a memoria inválida o a código controlado por el atacante para hacer que el dispositivo entre en un estado de fallo irrecuperable durante el arranque, lo que resulta en la pérdida permanente de operatividad.

20 May 2026, 14:16

Type Values Removed Values Added
References
  • {'url': 'https://www.ledger.com/security-bulletin', 'source': 'disclosure@vulncheck.com'}
  • () https://donjon.ledger.com/lsb/021/ -

19 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 22:16

Updated : 2026-07-24 09:10


NVD link : CVE-2025-15645

Mitre link : CVE-2025-15645

CVE.ORG link : CVE-2025-15645


JSON object : View

Products Affected

No product.

CWE
CWE-1284

Improper Validation of Specified Quantity in Input