Advisories

AuntyFey Smart Combination Lock BLE Connection Flood DoS

Go Back
severity
medium
date
Affecting
  • AuntyFey Smart Combination Lock firmware versions as of 2026-01-06

  • This vulnerability has not been addressed by the supplier

CWE
  • CWE-770 Allocation of Resources Without Limits or Throttling
CVSS
5.3
CVSS V4 Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Credit
Jabari Lucien (nsm_barii)
Description
AuntyFey Smart Combination Lock firmware versions as of 2026-01-06 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.