{
  "project": "OpenBeken",
  "repo_url": "https://github.com/openshwprojects/OpenBK7231T_App",
  "description": "Alternative firmware for BK7231, ESP32 and other Wi-Fi smart-home chips.",
  "release": {
    "filename": "oss-openshwprojects__OpenBK7231T_App.cdx.json",
    "analysed_at": "2026-10-11T07:00:43.940Z"
  },
  "computed_at": "2026-10-11T13:04:04.013Z",
  "summary": {
    "fix": 4,
    "look": 3,
    "clear": 3,
    "unwatched": 37,
    "missed_by_nvd_scanners": 20
  },
  "components": 47,
  "fix": [
    {
      "name": "mbedtls",
      "version": "3.6.4",
      "action": "Upgrade to 3.6.7 or later",
      "vulns": [
        {
          "id": "CVE-2025-59438",
          "title": "Padding oracle through timing of cipher error reporting",
          "severity": "critical",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-59438",
            "https://www.cve.org/CVERecord?id=CVE-2025-59438"
          ]
        },
        {
          "id": "CVE-2026-50580",
          "title": "Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-ecdhe-psk-client-buffer-overflow/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50580"
          ]
        },
        {
          "id": "CVE-2026-49300",
          "title": "X.509 CA bit forgery via invalid basicConstraints extension",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-x509-ca-bit-forgery-invalid-basicconstraints/",
            "https://www.cve.org/CVERecord?id=CVE-2026-49300"
          ]
        },
        {
          "id": "CVE-2026-50579",
          "title": "Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-use-after-free-pkcs7-free-reused-context/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50579"
          ]
        },
        {
          "id": "CVE-2026-25835",
          "title": "PSA random generator cloning",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-25835",
            "https://www.cve.org/CVERecord?id=CVE-2026-25835"
          ]
        },
        {
          "id": "CVE-2026-50713",
          "title": "Heap corruption with early renegotiation after corrupted record in DTLS",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-heap-corruption-early-renegotiation-corrupted-dtls-record/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50713"
          ]
        },
        {
          "id": "CVE-2026-50584",
          "title": "ChaCha20 counter overflow can reuse keystream",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-chacha20-counter-overflow-keystream-reuse/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50584"
          ]
        },
        {
          "id": "CVE-2026-50587",
          "title": "Timing side-channel in RSA PKCS#1 v1.5 decryption",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-rsa-pkcs1-v15-decryption-timing-side-channel/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50587"
          ]
        },
        {
          "id": "CVE-2026-35336",
          "title": "Possible buffer overflow in mbedtls_ecdh_calc_secret()",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-possible-buffer-overflow-ecdh-calc-secret/",
            "https://www.cve.org/CVERecord?id=CVE-2026-35336"
          ]
        },
        {
          "id": "CVE-2026-50640",
          "title": "Ignored TLS 1.3 resumption secret derivation error",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-ignored-tls13-resumption-secret-derivation-error/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50640"
          ]
        },
        {
          "id": "CVE-2026-25833",
          "title": "Buffer underflow in x509_inet_pton_ipv6()",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-25833",
            "https://www.cve.org/CVERecord?id=CVE-2026-25833"
          ]
        },
        {
          "id": "CVE-2026-50583",
          "title": "Out-of-bounds read when parsing a zero-length ECC public key",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-zero-length-ecc-public-key-oob-read/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50583"
          ]
        },
        {
          "id": "CVE-2026-25834",
          "title": "Signature Algorithm Injection",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-25834",
            "https://www.cve.org/CVERecord?id=CVE-2026-25834"
          ]
        },
        {
          "id": "CVE-2026-50581",
          "title": "Extended master secret calculation failure ignored",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-extended-master-secret-calculation-failure-ignored/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50581"
          ]
        },
        {
          "id": "CVE-2026-50586",
          "title": "Information disclosure in TLS 1.2 NewSessionTicket",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-newsessionticket-information-disclosure/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50586"
          ]
        },
        {
          "id": "CVE-2025-54764",
          "title": "Side channel in RSA key generation and operations",
          "severity": "critical",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-54764",
            "https://www.cve.org/CVERecord?id=CVE-2025-54764"
          ]
        },
        {
          "id": "CVE-2026-34873",
          "title": "Client impersonation while resuming a TLS 1.3 session",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-34873",
            "https://www.cve.org/CVERecord?id=CVE-2026-34873"
          ]
        },
        {
          "id": "CVE-2026-34875",
          "title": "Buffer overflow in FFDH public key export",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-34875",
            "https://www.cve.org/CVERecord?id=CVE-2026-34875"
          ]
        },
        {
          "id": "CVE-2026-34876",
          "title": "CCM multipart finish tag-length validation bypass",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-34876",
            "https://www.cve.org/CVERecord?id=CVE-2026-34876"
          ]
        },
        {
          "id": "CVE-2026-34874",
          "title": "Null pointer dereference when setting a distinguished name",
          "severity": "high",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-34874",
            "https://www.cve.org/CVERecord?id=CVE-2026-34874"
          ]
        },
        {
          "id": "CVE-2026-34872",
          "title": "FFDH: lack of contributory behaviour due to improper input validation",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-34872",
            "https://www.cve.org/CVERecord?id=CVE-2026-34872"
          ]
        },
        {
          "id": "CVE-2026-73096",
          "title": "TLS 1.3 early data integrity failure due to buffered plaintext across key change",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls13-early-data-integrity-failure-key-change/",
            "https://www.cve.org/CVERecord?id=CVE-2026-73096"
          ]
        },
        {
          "id": "CVE-2026-54435",
          "title": "Side channel leak in ECC optimized modp",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-ecc-optimized-modp-side-channel/",
            "https://www.cve.org/CVERecord?id=CVE-2026-54435"
          ]
        },
        {
          "id": "CVE-2026-50585",
          "title": "Incomplete context reset in mbedtls_ssl_session_reset()",
          "severity": "medium",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-ssl-session-reset-incomplete-context-reset/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50585"
          ]
        },
        {
          "id": "CVE-2026-54441",
          "title": "Signature algorithm restrictions not enforced on certificate chain",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-signature-algorithm-restrictions-certificate-chain/",
            "https://www.cve.org/CVERecord?id=CVE-2026-54441"
          ]
        },
        {
          "id": "CVE-2026-73064",
          "title": "A random generator fault can compromise TLS data integrity",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-random-generator-fault-tls-integrity/",
            "https://www.cve.org/CVERecord?id=CVE-2026-73064"
          ]
        },
        {
          "id": "CVE-2025-66442",
          "title": "Compiler-induced constant-time violations",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-66442",
            "https://www.cve.org/CVERecord?id=CVE-2025-66442"
          ]
        },
        {
          "id": "CVE-2026-34871",
          "title": "Entropy on Linux can fall back to /dev/urandom",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-34871",
            "https://www.cve.org/CVERecord?id=CVE-2026-34871"
          ]
        },
        {
          "id": "CVE-2026-34877",
          "title": "Risk of insufficient protection of serialized session or context data leading to potential memory safety issues",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-34877",
            "https://www.cve.org/CVERecord?id=CVE-2026-34877"
          ]
        },
        {
          "id": "CVE-2026-50588",
          "title": "Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing",
          "severity": "low",
          "vendor": "mbedtls",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-tls12-ecjpake-serverkeyexchange-oob-read/",
            "https://www.cve.org/CVERecord?id=CVE-2026-50588"
          ]
        }
      ]
    },
    {
      "name": "nimble",
      "version": "1.6.0",
      "action": "Upgrade to 1.10.0 or later",
      "vulns": [
        {
          "id": "CVE-2026-45815",
          "title": "Remote reachable assertion in ATT Read Multiple Variable Response handler",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45815",
            "https://www.cve.org/CVERecord?id=CVE-2026-45815"
          ]
        },
        {
          "id": "CVE-2025-52435",
          "title": "Invalid error handling in pause encryption procedure in NimBLE controller",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-52435",
            "https://www.cve.org/CVERecord?id=CVE-2025-52435"
          ]
        },
        {
          "id": "CVE-2025-62235",
          "title": "Incorrect handling of SMP Security Request could lead to undesirable pairing",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-62235",
            "https://www.cve.org/CVERecord?id=CVE-2025-62235"
          ]
        },
        {
          "id": "CVE-2024-51569",
          "title": "Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-51569",
            "https://www.cve.org/CVERecord?id=CVE-2024-51569"
          ]
        },
        {
          "id": "CVE-2026-45813",
          "title": "Incorrect data validation in BASS add/modify source operation",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45813",
            "https://www.cve.org/CVERecord?id=CVE-2026-45813"
          ]
        },
        {
          "id": "CVE-2026-45811",
          "title": "Buffer overflow in socket HCI transport",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45811",
            "https://www.cve.org/CVERecord?id=CVE-2026-45811"
          ]
        },
        {
          "id": "CVE-2025-53477",
          "title": "NULL Pointer Dereference in NimBLE host HCI layer",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-53477",
            "https://www.cve.org/CVERecord?id=CVE-2025-53477"
          ]
        },
        {
          "id": "CVE-2026-45816",
          "title": "NULL pointer dereference vulnerability in SMP LTK request",
          "severity": "high",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45816",
            "https://www.cve.org/CVERecord?id=CVE-2026-45816"
          ]
        },
        {
          "id": "CVE-2026-45812",
          "title": "OOB Read via sizeof(pointer) in Legacy Advertising Report Handler",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-45812",
            "https://www.cve.org/CVERecord?id=CVE-2026-45812"
          ]
        },
        {
          "id": "CVE-2024-47249",
          "title": "Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2024-47249",
            "https://www.cve.org/CVERecord?id=CVE-2024-47249"
          ]
        },
        {
          "id": "CVE-2026-46452",
          "title": "Mesh Proxy SAR reassembly unbounded append and unchecked failure",
          "severity": "medium",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2026-46452",
            "https://www.cve.org/CVERecord?id=CVE-2026-46452"
          ]
        },
        {
          "id": "CVE-2025-53470",
          "title": "Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver",
          "severity": "low",
          "vendor": "nimble",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-53470",
            "https://www.cve.org/CVERecord?id=CVE-2025-53470"
          ]
        }
      ]
    },
    {
      "name": "esp-idf",
      "version": "5.5.1",
      "action": "Upgrade to 5.5.2 or later",
      "vulns": [
        {
          "id": "CVE-2025-66409",
          "title": "Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-66409",
            "https://www.cve.org/CVERecord?id=CVE-2025-66409"
          ]
        },
        {
          "id": "CVE-2025-65092",
          "title": "ESP32-P4 JPEG Decoder Header Parsing Vulnerability",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/espressif/esp-idf/security/advisories/GHSA-vcw6-jc3p-4gj8",
            "https://www.cve.org/CVERecord?id=CVE-2025-65092"
          ]
        },
        {
          "id": "CVE-2025-68474",
          "title": "Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-68474",
            "https://www.cve.org/CVERecord?id=CVE-2025-68474"
          ]
        },
        {
          "id": "CVE-2025-64342",
          "title": "ESP32 Bluetooth Controller Invalid Access Address Vulnerability",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/espressif/esp-idf/security/advisories/GHSA-8mg7-9qpg-p92v",
            "https://www.cve.org/CVERecord?id=CVE-2025-64342"
          ]
        },
        {
          "id": "CVE-2025-68473",
          "title": "Out-of-Bounds Write in ESP32 Bluetooth SDP Result Handling",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2025-68473",
            "https://www.cve.org/CVERecord?id=CVE-2025-68473"
          ]
        },
        {
          "id": "CVE-2020-26142",
          "title": "Vulnerable Espressif WLAN device processes every single fragmented AMPDU frame as an independent and a full frame",
          "severity": "medium",
          "vendor": "espressif",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://www.espressif.com/sites/default/files/advisory_downloads/AR2023-008%20Security%20Advisory%20for%20WLAN%20FragAttacks%20EN.pdf",
            "https://www.cve.org/CVERecord?id=CVE-2020-26142"
          ]
        }
      ]
    },
    {
      "name": "berry",
      "version": "1.1.0..",
      "action": "Listed for this exact version. Open the CVEs to find the fix.",
      "vulns": [
        {
          "id": "CVE-2026-3285",
          "title": "berry-lang berry be_lexer.c scan_string out-of-bounds",
          "severity": null,
          "vendor": "OSV",
          "exploited": false,
          "nvd_scanner": null,
          "links": [
            "https://osv.dev/vulnerability/CVE-2026-3285"
          ]
        }
      ]
    }
  ],
  "look": [
    {
      "name": "lwip",
      "version": "2.2.0",
      "action": "A vendor fork: check whether it carries the fixes",
      "vulns": [
        {
          "id": "CVE-2020-22283",
          "title": "Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information",
          "severity": "high",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://nvd.nist.gov/vuln/detail/CVE-2020-22283",
            "https://www.cve.org/CVERecord?id=CVE-2020-22283"
          ]
        }
      ]
    },
    {
      "name": "openthread",
      "version": null,
      "action": "A vendor fork with no release version. Check the vendor's notes on these advisories.",
      "vulns": [
        {
          "id": "CVE-2023-41095",
          "title": "Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices",
          "severity": "high",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": true,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/400-499/A-00000482.md",
            "https://www.cve.org/CVERecord?id=CVE-2023-41095"
          ]
        },
        {
          "id": "CVE-2023-2626",
          "title": "Missing Key ID Mode validation when processing 6LoWPAN frames",
          "severity": "high",
          "vendor": "openthread",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://github.com/openthread/openthread/security/advisories/GHSA-vr3r-363g-72j9",
            "https://www.cve.org/CVERecord?id=CVE-2023-2626"
          ]
        },
        {
          "id": "CVE-2023-41096",
          "title": "Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices",
          "severity": "high",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/400-499/A-00000482.md",
            "https://www.cve.org/CVERecord?id=CVE-2023-41096"
          ]
        },
        {
          "id": "A-00000463",
          "title": "OpenThread Vulnerability - Key ID Mode 2 Security",
          "severity": "high",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/400-499/A-00000463.md"
          ]
        },
        {
          "id": "CVE-2023-45199",
          "title": "Due to a buffer overflow in TLS handshake processing, a malicious peer may be able to gain remote code execution by sending overly long packets",
          "severity": "medium",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/400-499/A-00000492.md",
            "https://www.cve.org/CVERecord?id=CVE-2023-45199"
          ]
        },
        {
          "id": "CVE-2023-41097",
          "title": "Due to a padding oracle, attackers with access to precise time measurement may be able to learn confidential information protected by AES-CBC or RSA OAEP without requiring key information",
          "severity": "medium",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/400-499/A-00000492.md",
            "https://www.cve.org/CVERecord?id=CVE-2023-41097"
          ]
        },
        {
          "id": "CVE-2025-2329",
          "title": "Heavy traffic environment results in denial of service",
          "severity": "medium",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/500-599/A-00000533.md",
            "https://www.cve.org/CVERecord?id=CVE-2025-2329"
          ]
        },
        {
          "id": "A-00000492",
          "title": "A bug in TLS MAC length calculation may cause a buffer overread",
          "severity": "medium",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/400-499/A-00000492.md"
          ]
        }
      ]
    },
    {
      "name": "coex-lib",
      "version": null,
      "action": "Bundled in an SDK with no version of its own. Check the advisories.",
      "vulns": [
        {
          "id": "CVE-2021-26706",
          "title": "Update to “BadAlloc” Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations",
          "severity": "medium",
          "vendor": "silabs",
          "exploited": false,
          "nvd_scanner": false,
          "links": [
            "https://raw.githubusercontent.com/SiliconLabsSoftware/docs-security-advisories/main/Advisories/200-299/A-00000279.md",
            "https://www.cve.org/CVERecord?id=CVE-2021-26706"
          ]
        }
      ]
    }
  ],
  "unwatched": [
    {
      "name": "beken-freertos-sdk",
      "version": "f5a64d4cda03bac6d885f4f30c27bbd3435c5e3a"
    },
    {
      "name": "bouffalo-sdk",
      "version": "2.3.26..2.3.27"
    },
    {
      "name": "cmock",
      "version": "v2.5.2-2-geeecc49ce8af"
    },
    {
      "name": "esp-ble-mesh-lib",
      "version": null
    },
    {
      "name": "esp-phy-lib",
      "version": null
    },
    {
      "name": "esp-thread-lib",
      "version": null
    },
    {
      "name": "esp32-bt-lib",
      "version": null
    },
    {
      "name": "esp32-wifi-lib",
      "version": null
    },
    {
      "name": "esp32c2-bt-lib",
      "version": null
    },
    {
      "name": "esp32c3-bt-lib",
      "version": null
    },
    {
      "name": "esp32c5-bt-lib",
      "version": null
    },
    {
      "name": "esp32c6-bt-lib",
      "version": null
    },
    {
      "name": "esp32h2-bt-lib",
      "version": null
    },
    {
      "name": "mqtt",
      "version": null
    },
    {
      "name": "openbk7231n",
      "version": "07fd9e0e2da0aabaddab00be2a897589be235158"
    },
    {
      "name": "openbk7231t",
      "version": "d9411f8808990d8e1dc3767f3aa548a7444e1c01"
    },
    {
      "name": "openbk7239n",
      "version": "3f1b4f4ce1798a7d062467160f64dea37020f9ee"
    },
    {
      "name": "openbl602",
      "version": "e0efddc364037ed2b2cd79dae3e51f3e21a75177"
    },
    {
      "name": "openecr6600",
      "version": "1aa42baa4cbb0781c716f75da28b6371da81215c"
    },
    {
      "name": "openesp8266",
      "version": "67a4c26e81ab8b7703c3cf9e4a9178c6245ba277"
    },
    {
      "name": "opengd32vw553",
      "version": "8b859b21d57bc6b508dc13675c222c893aaec767"
    },
    {
      "name": "openln8825",
      "version": "2.0.."
    },
    {
      "name": "openln882h",
      "version": "84149f251efc120561bdefa17ce399f62eadb8be"
    },
    {
      "name": "openrda5981",
      "version": "46cd5bf6b352615ce4ba0c44ce8634855a233ebc"
    },
    {
      "name": "openrtl8710a-b",
      "version": "5d8d26b2cb68f4041a48cca6beae6eb69f34456a"
    },
    {
      "name": "openrtl8720d",
      "version": "ad3d02c713286a1da04e7025d0aa74f5214080dc"
    },
    {
      "name": "openrtl87x0c",
      "version": "1e7a2048dc97d1bd37bd62fffc2d49c422ca214a"
    },
    {
      "name": "opentr6260",
      "version": "a6f72569d0fa195396440bb018d87a43595f334b"
    },
    {
      "name": "opentxw81x",
      "version": "05bd1742cd07e6d91f1276ca87baae374e156798"
    },
    {
      "name": "openw600",
      "version": "db909ce9100e389f45c9ccfd155f755b8dd3a350"
    },
    {
      "name": "openw800",
      "version": "f917fe93389846f7762e1f40b2cf9593749ad760"
    },
    {
      "name": "openxr806",
      "version": "3113bbb32f8378206f52d72406aa123a1368bfec"
    },
    {
      "name": "openxr809",
      "version": "b35b75ce118dc25ecdf0d767f79a5f5dac5144cf"
    },
    {
      "name": "openxr872",
      "version": "84deedb8e2014e6b5252f2b21055fa31eb3d4b90"
    },
    {
      "name": "spiffs",
      "version": "0.2-255-g0dbb3f71c5f6"
    },
    {
      "name": "tlsf",
      "version": null
    },
    {
      "name": "unity",
      "version": "v2.6.0-RC1"
    }
  ]
}