Junglewise Threat Intelligence

CVE-2025-36939: OpenThread MLE packet handling denial of service

CVE-2025-36939 · Severity: medium · CVSS 5.7 · Published 2026-08-24

Vendors: Google.

Executive brief

OpenThread is a networking stack used in IoT and smart home devices to enable Thread mesh network communication. An authenticated attacker on the same Thread network can send malicious packets to crash devices running vulnerable versions, disrupting network connectivity and device availability. The vulnerability includes both assertion failures and a buffer overflow that can cause denial of service.

Technical details

Multiple vulnerabilities exist in OpenThread's MLE (Mesh Link Establishment) packet handling. The issues include triggerable assertion failures and a stack-based buffer overflow in packet processing. An authenticated attacker on the same Thread network can send specially crafted MLE packets to trigger these conditions. Successful exploitation results in denial of service through process crash or hang. Patch availability and specific affected versions should be verified from the Google/Nest security bulletin.

Affected products

  • Google OpenThread

Timeline

  • 2026-08-24: disclosed

References