๐Ÿ” CVE Alert

CVE-2026-47773

UNKNOWN 0.0

ArduinoBLE: Memory corruption via malformed ATT write request

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt memory in the ATTClass global object. Devices running ArduinoBLE with one or more characteristics configured with the BLEEncryption property are affected. The fix is included starting from the 2.0.2 release.

CWE CWE-131 CWE-787
Vendor arduino-libraries
Product arduinoble
Published Sep 11, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for arduino-libraries arduinoble

Be the first to know when new unknown vulnerabilities affecting arduino-libraries arduinoble are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

arduino-libraries / ArduinoBLE
< 2.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/arduino-libraries/ArduinoBLE/security/advisories/GHSA-77v6-cw9f-9whg github.com: https://github.com/arduino-libraries/ArduinoBLE/pull/431/changes/1460e1a68221fca854b7b1e278cab76e763c00e6 github.com: https://github.com/arduino-libraries/ArduinoBLE/releases/tag/2.0.2