CVE-2025-15474 Details
Description
AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device.
A denial-of-service vulnerability has been identified in the AuntyFey Smart Combination Lock, specifically in the firmware versions available as of January 6, 2026. This vulnerability allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to disrupt the lock's functionality by repeatedly initiating BLE connections. These sustained connection attempts interfere with the keypad authentication process, forcing the device into lockout states every 10 to 15 seconds. As a result, legitimate users are unable to unlock the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 7, 2026CISA-ADP
Assessed Jan 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nsm-barii/ble-smartlock-dos | [email protected] | ExploitTechnical Description |
| https://www.amazon.com/dp/B0F9L1M4XG | [email protected] | ProductVendor |
| https://www.vulncheck.com/advisories/auntyfey-smart-combination-lock-ble-connection-flood-dos | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AuntyFey Smart Combination Lock | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 7, 2026 | New CVE Received | [email protected] |
Volerion