CVE-2025-15645

MEDIUM

Ledger Nano X, Flex, Stax MCU Firmware Update Denial of Service

Title source: cna
STIX 2.1

Description

Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause the device to enter an unrecoverable fault state during boot, resulting in permanent loss of operability.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
Ledger Security Bulletin 021
https://www.ledger.com/security-bulletin
Vendor Advisory vendor-advisory
Ledger Security Bulletin 021
https://donjon.ledger.com/lsb/021/

Scores

CVSS v3 4.6
EPSS 0.0021
EPSS Percentile 11.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1284
Status published
Products (3)
Ledger/Ledger Flex < 1.2.2
Ledger/Ledger Nano X < 2.4.2
Ledger/Ledger Stax < 1.6.2
Published May 19, 2026
Tracked Since May 19, 2026