PT-2025-50499 · Meatmeet · Meatmeet

Published

2025-12-10

·

Updated

2026-01-21

·

CVE-2025-65824

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Meatmeet (affected versions not specified)
Description An attacker in close proximity can execute code remotely on the Meatmeet device by performing an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy (BLE). The device does not verify the authenticity of firmware updates, allowing an attacker to overwrite the device’s firmware with malicious code. This results in Remote Code Execution (RCE) and complete loss of device access for the user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-65824

Affected Products

Meatmeet