CVE-2026-65058

MEDIUM

Trezor Safe improper security check in on-device display

Title source: cna
STIX 2.1

Description

Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c.

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-358
Status published
Products (6)
Trezor/Safe 3 < 70c9b0c
Trezor/Safe 3 70c9b0c
Trezor/Safe 5 < 70c9b0c
Trezor/Safe 5 70c9b0c
Trezor/Safe 7 < 70c9b0c
Trezor/Safe 7 70c9b0c
Published Jul 21, 2026
Tracked Since Jul 22, 2026