VulnSea

csa-iot has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was July 2026 with 5. The median CVSS is 5.7 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-617 (3).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
5.7
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • matter 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

csa-iot vulnerabilities

CVEs affecting csa-iot, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2025-56365Medium· 5.7PoC
2mo ago

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the …

▾ Twilightcsa-iot · matterEPSS 0.62%via NVD
CVE-2025-56364Medium· 5.7PoC
2mo ago

A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists

A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an…

▾ Twilightcsa-iot · matterEPSS 0.58%via NVD
CVE-2025-56363Medium· 5.7PoC
2mo ago

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.)

A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks …

▾ Twilightcsa-iot · matterEPSS 0.59%via NVD
CVE-2025-56362Medium· 5.7PoC
2mo ago

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is sent and immediately followed by a wri…

▾ Twilightcsa-iot · matterEPSS 0.58%via NVD
CVE-2025-56361Medium· 5.7PoC
2mo ago

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`)

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command i…

▾ Twilightcsa-iot · matterEPSS 0.58%via NVD
csa-iot vulnerabilities (CVEs) · VulnSea