Trezor manufactures hardware cryptocurrency wallets and their accompanying bridge software, presenting a narrow but high-value attack surface centered on devices that store and manage cryptographic keys. Observed vulnerabilities cluster around code-injection risks in the bridge interface and observable discrepancies in the device firmware, reflecting the security-critical nature of key-handling and device-communication layers in hardware wallet design. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trezor over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-18172CRITICAL A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges. | Jul 26, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-14353MEDIUM On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illumina | Aug 8, 2019 | 4.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trezor.
Media articles that mention a CVE ID that affects a product developed by Trezor — matched by CVE ID, not by vendor name.