{"id":"CVE-2025-15474","title":"AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connecti…","summary":"AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connecti…","severity":"none","cwe":["CWE-770"],"published":"2026-01-07","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15474","references":[{"url":"https://github.com/nsm-barii/ble-smartlock-dos","label":"disclosure@vulncheck.com"},{"url":"https://www.amazon.com/dp/B0F9L1M4XG","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/auntyfey-smart-combination-lock-ble-connection-flood-dos","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"epss":0.00331,"epssPercentile":0.23769,"exploits":{"github":1,"githubRepos":["https://github.com/NSM-Barii/CVE-2025-15474"],"checkedAt":"2026-09-30T22:28:02.732Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T22:27:27.718Z","slug":"CVE-2025-15474","body":"## Overview\n\nAuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}