https://seclists.org/oss-sec/2026/q1/42: CVE-2025-62235: Apache NimBLE: Incorct handling of SMP Security quest could lead to undesirable pairing
Published Jan 8, 2026
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.8.0
Frequently Asked Questions
1
What is the severity of CVE-2025-62235?
The severity of CVE-2025-62235 is classified as important.
2
What versions of Apache NimBLE are affected by CVE-2025-62235?
CVE-2025-62235 affects Apache NimBLE versions up to and including 1.8.0.
3
What is the nature of the vulnerability described in CVE-2025-62235?
CVE-2025-62235 is an Authentication Bypass by Spoofing vulnerability that could lead to undesirable pairing.
4
What could happen if CVE-2025-62235 is exploited?
Exploitation of CVE-2025-62235 could allow an impostor to remove an original bond and re-bond with a device.
5
How do I mitigate CVE-2025-62235?
To mitigate CVE-2025-62235, you should upgrade to a fixed version of Apache NimBLE that addresses this vulnerability.