VYPR

Trezor One

by Trezor

CVEs (4)

  • CVE-2024-23660HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in…

  • CVE-2020-14199MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed…

  • CVE-2025-69893MedApr 14, 2026
    risk 0.30cvss 4.6epss 0.00

    A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which…

  • CVE-2019-14353MedAug 8, 2019
    risk 0.27cvss 4.2epss 0.00

    On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the…