Description
ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt memory in the ATTClass global object. Devices running ArduinoBLE with one or more characteristics configured with the BLEEncryption property are affected. The fix is included starting from the 2.0.2 release.
Published: 2026-09-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption leading to potential remote code execution
Action: Patch Now
AI Analysis

Impact

A missing bounds check in the ATT layer write request handler of ArduinoBLE allows a remote unauthenticated BLE client to send a malformed ATT write request that corrupts the global ATTClass instance. The corruption is a buffer‑size relational error and an out‑of‑bounds write, which can lead to arbitrary code execution or device denial of service.

Affected Systems

The vulnerability exists in the ArduinoBLE library for Arduino models that include the library. Devices running versions before 2.0.2, especially those with characteristics configured with the BLEEncryption property, are vulnerable.

Risk and Exploitability

The flaw has a CVSS score of 7.2, a high vulnerability level. The EPSS score of <1% indicates that exploitation attempts are unlikely, although a known attack scenario exists. Because the bug is not yet cataloged in KEV, it has not been widely reported as exploited, but any device that has not updated to 2.0.2 remains at risk of remote code execution through a simple BLE request.

Generated by OpenCVE AI on September 15, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the ArduinoBLE library to version 2.0.2 or later
  • Recompile and flash the firmware using the updated library
  • Remove or disable any BLEEncryption characteristics that are not required

Generated by OpenCVE AI on September 15, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arduino-libraries
Arduino-libraries arduinoble
Vendors & Products Arduino-libraries
Arduino-libraries arduinoble

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt memory in the ATTClass global object. Devices running ArduinoBLE with one or more characteristics configured with the BLEEncryption property are affected. The fix is included starting from the 2.0.2 release.
Title ArduinoBLE: Memory corruption via malformed ATT write request
Weaknesses CWE-131
CWE-787
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Arduino-libraries Arduinoble
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T16:41:28.114Z

Reserved: 2026-05-19T22:36:16.882Z

Link: CVE-2026-47773

cve-icon Vulnrichment

Updated: 2026-09-15T16:41:19.368Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T21:17:09.940

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-47773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-787

    Out-of-bounds Write