Junglewise Threat Intelligence

CVE-2025-44525: Texas Instruments SimpleLink SDK insufficient bounds check in BLE Link Layer

CVE-2025-44525 · Severity: medium · CVSS 6.5 · Published 2025-07-09

Executive brief

A vulnerability exists in the software development kit for Texas Instruments CC2652RB LaunchPad devices, which are used to build wireless connectivity into various products. An attacker within Bluetooth range can send a specially crafted signal that tricks the device into shrinking its data reception capacity to an unusable size. This results in a 'soft deadlock' where the device remains powered on but can no longer receive or process standard communication, effectively knocking it offline.

Technical details

A Denial of Service (DoS) vulnerability exists in the BLE Link Layer of the Texas Instruments SimpleLink CC13XX CC26XX SDK version 7.41.00.17. The stack fails to enforce the minimum bound of 27 bytes for the MaxRxOctets field during the LL Data Length Update procedure, as required by the Bluetooth Core Specification. An adjacent attacker can establish a BLE connection and transmit an LL_LENGTH_REQ packet with an invalid MaxRxOctets value (e.g., 5 bytes). If accepted, the peripheral's receive buffer is degraded, causing it to silently drop any subsequent packets larger than the specified value, resulting in a semantic deadlock and communication failure.

Affected products

  • Texas Instruments SimpleLink CC13XX CC26XX SDK 7.41.00.17

Timeline

  • 2025-07-09: advisory: NVD publication date

References