CVE-2025-65824 describes a critical vulnerability in Meatmeet Pro Wi-Fi & Bluetooth Meat Thermometers and their firmware. An unauthenticated attacker in close proximity can leverage Bluetooth Low Energy (BLE) to perform an unauthorized firmware upgrade, overwriting the device's firmware with malicious code due to a lack of integrity checks. This allows for Remote Code Execution (RCE), leading to complete loss of access for the legitimate user. The vulnerability carries a high CVSS score of 8.8, indicating a severe risk. Its attack vector is adjacent (AV:A) and requires no user interaction (UI:N) or privileges (PR:N), making it easily exploitable with low attack complexity (AC:L). The potential impact is high across confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.34.4CPE matchmatch criteria | cpe:2.3:o:meatmeet:meatmeet_pro_wifi_\&_bluetooth_meat_thermometer_firmware:1.0.34.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.