CVE-2025-15645
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. An attacker can provide a crafted reset_handler address pointing to invalid memory or attacker-controlled code to cause the device to enter an unrecoverable fault state during boot, resulting in permanent loss of operability.
Published:May 19, 2026
Last Modified:Jul 14, 2026
EPS:May 19, 2026
EPSS Score:0.0021
CVSS Score:4.6
Affected Products
Vendor
Product
Action
Vendor
Ledger
Product
Flex
Ledger
Flex
Vendor
Ledger
Product
Nano X
Ledger
Nano X
Vendor
Ledger
Product
Stax
Ledger
Stax
Vendor
Ledger-cli
Product
Ledger
Ledger-cli
Ledger
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
