High7.7
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

PT-2025-41: The Twinkly Light Tree 3D firmware uses a vulnerable Blufi library

Error type:

  • CWE-120:Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-131:Incorrect Calculation of Buffer Size

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/ AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 7.7 (high)

Description:

The vulnerability was identified in the Twinkly Light Tree 3D firmware, 2.8.18.

An attacker within Bluetooth range, with physical access to a device running firmware prior to 2.9.0 and provisioning mode manually re-enabled could, in an attack scenario, interfere with the provisioning exchange and potentially read memory data, compromise the device or install unauthorized firmware.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: August 2025

Recommendations:

Firmware version 2.9.0 fully addresses this issue by:

  • Patching the provisioning logic in line with Espressif’s recommendations
  • Improving input validation
  • Reinforcing encryption during the provisioning handshake
  • Adding anti-downgrade protection to prevent rollback to previous firmware versions

Additional information: 

Researcher: Alexey Shalpegin (Positive Technologies)

Identifiers:

CVE-2025-55297

BDU:2025-11161

Vendor:

Ledworks S.R.L.

Vulnerable product:

Twinkly Light Tree 3D

Vulnerable versions:

prior to 2.9.0