Multiple Vulnerabilities in OpenThread Could Lead to Denial of Service
CVE-2025-36939

10CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2025-36939?

OpenThread has multiple vulnerabilities related to the handling of MLE packets. An authenticated attacker on the same Thread network could exploit these flaws by sending specially crafted packets, potentially resulting in a denial of service. The vulnerabilities include assertion failures that can be triggered intentionally as well as a stack-based buffer overflow, which could further compromise the stability of the network.

Affected Version(s)

Nest 3.78.518349

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.