VYPR
High severity8.1OSV Advisory· Published Jan 10, 2026· Updated Jun 17, 2026

CVE-2025-62235

CVE-2025-62235

Description

Authentication Bypass by Spoofing vulnerability in Apache NimBLE.

Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0.

Users are recommended to upgrade to version 1.9.0, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Apache/NimBLEllm-fuzzy2 versions
    <=1.8.0+ 1 more
    • (no CPE)range: <=1.8.0
    • cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*range: <1.9.0
  • Apache/Mynewt Nimblellm-fuzzy2 versions
    <=1.8.0+ 1 more
    • (no CPE)range: <=1.8.0
    • (no CPE)range: nimble_1_5_0_rc1_tag, nimble_1_5_0_tag, nimble_1_6_0_rc1_tag, …

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.