Medium severity6.5NVD Advisory· Published Aug 2, 2016· Updated Jun 17, 2026
CVE-2016-6257
CVE-2016-6257
Description
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:amazonbasics:firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:dell:km632_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:lenovo:ultraslim_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:logitech:unifying_firmware:*:*:*:*:*:*:*:*Range: <=012.005.00028
Patches
Vulnerability mechanics
References
4- www.securityfocus.com/bid/92179nvdThird Party AdvisoryVDB Entry
- github.com/BastilleResearch/keyjack/blob/master/doc/advisories/bastille-13.lenovo-ultraslim.public.txtnvdThird Party Advisory
- support.lenovo.com/product_security/len_7267nvdVendor Advisory
- www.bastille.net/research/vulnerabilities/keyjacknvdThird Party Advisory
News mentions
0No linked articles in our index yet.