CVE-2025-65824

An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE), resulting in the firmware on the device being overwritten with the attacker's code. As the device does not perform checks on upgrades, this results in Remote Code Execution (RCE) and the victim losing complete access to the Meatmeet.
Configurations

No configuration.

History

11 Dec 2025, 21:15

Type Values Removed Values Added
CWE CWE-306
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

10 Dec 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 21:16

Updated : 2025-12-12 15:18


NVD link : CVE-2025-65824

Mitre link : CVE-2025-65824

CVE.ORG link : CVE-2025-65824


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function