CVE-2025-36939

10.0

Google · Nest

Multiple vulnerabilities in OpenThread's handling of MLE packets in Google Nest allow unauthenticated attackers to cause a denial of service via buffer overflows or assertion failures.

Executive summary

A critical vulnerability in Google Nest firmware allows unauthenticated remote attackers to cause a denial of service, potentially impacting the stability and availability of the device.

Vulnerability

This vulnerability involves improper handling of Mesh Link Establishment (MLE) packets within the OpenThread stack. The flaw, which includes stack-based buffer overflows and assertion failures, can be triggered by an unauthenticated attacker sending malicious packets to the device.

Business impact

Successful exploitation leads to a denial of service, which can render Google Nest devices unresponsive or cause them to crash. Given the CVSS score of 10.0, this represents a critical risk to business continuity, particularly for environments relying on these devices for network management or security monitoring.

Remediation

Immediate Action: Update Google Nest firmware to the latest available version provided by the vendor.

Proactive Monitoring: Monitor network traffic for anomalous MLE packet patterns or sudden device reboots that may indicate exploitation attempts.

Compensating Controls: Ensure that Thread network segments are isolated from untrusted external traffic where possible to limit the reach of potential attackers.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

The critical nature of this vulnerability, combined with the lack of required authentication for an attacker, necessitates immediate patching. Organizations should prioritize updating all affected Google Nest hardware to the latest firmware to eliminate the risk of remote service disruption.

More Google CVEs