CVE-2026-5706EPSS p30.9%
CVE-2026-5706CVE-2026-5706
Description
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted.
Scoring
| EPSS | 0.39% probability of exploitation · percentile 30.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-08 |