Bluetooth Stack Vulnerability in Select Products by Vendor
CVE-2025-41657

4.3MEDIUM

Key Information:

Vendor

Auma

Vendor
CVE Published:
10 June 2025

What is CVE-2025-41657?

An undocumented active Bluetooth stack in select products poses a security risk by allowing unauthenticated adjacent attackers to fingerprint devices. This vulnerability impacts products delivered between January 1, 2024, and May 9, 2025, enabling potential exploitation through unauthorized observation of device characteristics.

Affected Version(s)

AC1.2 01.01.2024 < 09.05.2025

PROFOX 01.01.2024 < 09.05.2025

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.