Junglewise Threat Intelligence

CVE-2026-47773: Arduino ArduinoBLE buffer overflow in ATT write handler

CVE-2026-47773 · Severity: info · CVSS 0 · Published 2026-09-11

Executive brief

ArduinoBLE is a library that enables Bluetooth Low Energy connectivity on Arduino devices. Versions before 2.0.2 contain a missing bounds check that allows a remote attacker to overflow a buffer in the ATT (Attribute Protocol) layer, potentially corrupting device memory. Devices using BLE encryption features are at risk of malfunction or system compromise via wireless attacks from nearby attackers.

Technical details

The vulnerability is a buffer overflow in the ATTClass::writeReqOrCmd() function in src/utility/ATT.cpp. The vulnerable code fails to validate that write request data will fit within the writeBuffer before performing a memcpy() operation. An unauthenticated remote BLE client can craft an ATT write request with an oversized value field to trigger the overflow. The attack requires network-adjacent proximity (Bluetooth range) and affects devices with one or more BLE characteristics configured with the BLEEncryption property. A fix adding proper bounds checking was merged in May 2026 and released in version 2.0.2.

Affected products

  • Arduino ArduinoBLE prior to 2.0.2

Timeline

  • 2026-09-11: disclosed: CVE-2026-47773 published
  • 2026-05: patched: Fix merged in PR #431 (May 4-5, 2026)

References