Vulnerability vector:
- Base vulnerability score (CVSSv4.0): CVSS:4.0/ AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- Severity (CVSSv4.0): 7.7 (high)
Description:
The vulnerability was identified in the Twinkly Light Tree 3D firmware, 2.8.18.
An attacker within Bluetooth range, with physical access to a device running firmware prior to 2.9.0 and provisioning mode manually re-enabled could, in an attack scenario, interfere with the provisioning exchange and potentially read memory data, compromise the device or install unauthorized firmware.
Vulnerability status: Confirmed by vendor
Date of vulnerability remediation: August 2025
Recommendations:
Firmware version 2.9.0 fully addresses this issue by:
- Patching the provisioning logic in line with Espressif’s recommendations
- Improving input validation
- Reinforcing encryption during the provisioning handshake
- Adding anti-downgrade protection to prevent rollback to previous firmware versions
Additional information:
Researcher: Alexey Shalpegin (Positive Technologies)