Impact
The vulnerability is caused by a silent failure in the Zephyr TCP stack’s implementation of RFC 6528, which generates the initial sequence number (ISN) from a 128‑bit secret called unique_key. When the random source sys_csrand_get() fails, the unique_key remains all zeros and the once‑guard is incorrectly latched to true. The result is that the ISN becomes a predictable function of the connection four‑tuple and a global time offset, so an off‑path adversary can compute future ISNs offline, allowing blind TCP spoofing or data injection against any connection whose four‑tuple can be guessed. The weakness is a use of a single source of entropy, classified as CWE‑330.
Affected Systems
The affected product is the Zephyr real‑time operating system (Zephyr project: zephyr). Any device that uses the default TCP stack compiled with CONFIG_NET_TCP_ISN_RFC6528 enabled and relies on the sys_csrand_get() entropy source is subject, including embedded and IoT platforms that boot with this stack.
Risk and Exploitability
Exploitation requires a random‑source error during the first TCP connection after boot, which can be triggered by a reboot or an immediately listening service that opens a connection. Once the ISN key is seeded with an all‑zero value, the attacker can recover the shared time offset from a single observed ISN, after which all subsequent ISNs for that boot are fully predictable, enabling off‑path spoofing or injection. The CVSS score is 4.8, indicating low to medium severity, but the likelihood of exploitation is low and the vulnerability is not in the CISA KEV catalog. Nevertheless, on vulnerable embedded deployments the impact can be significant, especially in high‑trust or high‑availability scenarios.
OpenCVE Enrichment