CVE-2025-65825

MEDIUM

Meatmeet - Info Disclosure

Title source: llm
STIX 2.1

Description

The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect over UART, and retrieve the firmware dump for analysis. Within the NVS partition they may discover the credentials of the current and previous Wi-Fi networks. This information could be used to gain unauthorized access to the victim's Wi-Fi network.

Scores

CVSS v3 4.6
EPSS 0.0001
EPSS Percentile 2.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-311
Status published
Products (1)
meatmeet/meatmeet_pro_wifi_\&_bluetooth_meat_thermometer_firmware 1.0.34.4
Published Dec 10, 2025
Tracked Since Feb 18, 2026