---
id: CVE-2025-65828
title: >-
  An unauthenticated attacker within proximity of the Meatmeet device can issue
  several commands over Bluetooth Low Energy (BLE) to these devices which would
  result in a Denial of Service
summary: >-
  An unauthenticated attacker within proximity of the Meatmeet device can issue
  several commands over Bluetooth Low Energy (BLE) to these devices which would
  result in a Denial of Service. These commands include: shutdown, restart,
  clear c…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-306
vendor: meatmeet
product: meatmeet_pro_wifi_&_bluetooth_meat_thermometer_firmware
affected:
  - meatmeet_pro_wifi_&_bluetooth_meat_thermometer_firmware = 1.0.34.4
published: '2025-12-10'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65828'
references:
  - url: >-
      https://gist.github.com/dead1nfluence/4dffc239b4a460f41a03345fd8e5feb5#file-denial-of-service-ble-md
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00281
epssPercentile: 0.18358
ingestedAt: '2026-09-25T23:21:16.937Z'
---

## Overview

An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy (BLE) to these devices which would result in a Denial of Service. These commands include: shutdown, restart, clear config. Clear config would disassociate the current device from its user and would require re-configuration to re-enable the device. As a result, the end user would be unable to receive updates from the Meatmeet base station which communicates with the cloud services until the device had been fixed or turned back on.

## Affected

- `meatmeet_pro_wifi_&_bluetooth_meat_thermometer_firmware = 1.0.34.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
