CVE-2025-15645: Ledger Nano X, Flex, Stax MCU Firmware Update Denial of Service
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause the device to enter an unrecoverable fault state during boot, resulting in permanent loss of operability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15645?
CVE-2025-15645 is classified as a denial of service vulnerability.
How do I fix CVE-2025-15645?
Users should ensure that firmware updates for Ledger Nano X, Flex, and Stax devices are applied promptly after validation from Ledger.
What devices are affected by CVE-2025-15645?
CVE-2025-15645 affects Ledger Nano X, Ledger Nano Flex, and Ledger Stax devices.
What type of attack does CVE-2025-15645 enable?
CVE-2025-15645 enables an attacker to perform a denial of service during the firmware update process.
How can I verify if my Ledger device is vulnerable to CVE-2025-15645?
Users should check the Ledger security bulletin for updates regarding CVE-2025-15645 and recommended actions.