Texas Instruments CC2652RB LaunchPad Bluetooth Low Energy Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Texas Instruments CC2652RB LaunchPad, specifically within the SimpleLink CC13XX CC26XX SDK version 7.41.00.17. The issue arises from inadequate permission checks on critical fields in Bluetooth Low Energy (BLE) data packets. This flaw enables attackers to disrupt services by sending a crafted LL_Length_Req packet.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the device to become unresponsive or unavailable.

Reproduction

The vulnerability can be reproduced by sending a specially crafted LL_Length_Req packet to a device using the affected Texas Instruments CC2652RB LaunchPad and the specified SDK version. This packet manipulation takes advantage of the insufficient permission checks, causing a denial-of-service effect on the device.

Added: Jul 9, 2025, 5:42 PM
Updated: Jul 9, 2025, 5:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.