Vulnerabilities (CVE)

Filtered by CWE-239
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-41724 2025-10-22 N/A 7.5 HIGH
An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process will not be restarted by a watchdog and a device reboot is necessary to make it work again.
CVE-2024-29155 2025-08-29 N/A 4.3 MEDIUM
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.