Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause the device to enter an unrecoverable fault state during boot, resulting in permanent loss of operability.
References
Configurations
No configuration.
History
20 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
19 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 22:16
Updated : 2026-05-20 14:16
NVD link : CVE-2025-15645
Mitre link : CVE-2025-15645
CVE.ORG link : CVE-2025-15645
JSON object : View
Products Affected
No product.
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
