PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15474 AuntyFey CVE debrief

A CVE debrief for AuntyFey Smart Combination Lock firmware vulnerability. The AuntyFey Smart Combination Lock firmware contains a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. This vulnerability affects device management and security, particularly for defenders of AuntyFey Smart Combination Lock devices. The vulnerability can cause denial of service and interrupt legitimate user access.

Vendor
AuntyFey
Product
AuntyFey Smart Combination Lock
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders of AuntyFey Smart Combination Lock devices, particularly those responsible for device management and security, should be aware of this vulnerability and take steps to verify and mitigate it. They should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.

Why it matters

Defenders of AuntyFey Smart Combination Lock devices should be aware of this vulnerability and take steps to verify and mitigate it, as it can cause denial of service and interrupt legitimate user access.

  • Denial of service due to sustained connection attempts
  • Interrupted keypad authentication input
  • Repeatedly forced device into lockout states

Technical summary

The AuntyFey Smart Combination Lock firmware contains a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and repeatedly force the device into lockout states, preventing legitimate users from unlocking the device. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Defensive priority

Medium priority for defenders of AuntyFey Smart Combination Lock devices

Recommended defensive actions

  • Review and verify the firmware version of AuntyFey Smart Combination Lock devices
  • Implement monitoring for unusual BLE connection attempts
  • Restrict access to the device's BLE interface if possible
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but specific versions of the firmware and full scope of affected devices require verification from the vendor or official sources. Defenders should verify the firmware version of AuntyFey Smart Combination Lock devices and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15474 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15474

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15474 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15474

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.