MEDIUM · 6.8

CVE-2025-65829

The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can execute on the device. ...

Vulnerability Description

The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can execute on the device. The Secure Boot process forms a chain of trust by verifying all mutable software entities involved in the Application Startup Flow. As a result, an attacker with physical access to the device can flash modified firmware to the device, resulting in the execution of malicious code upon startup.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MeatmeetMeatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware1.0.34.4
MeatmeetMeatmeet Pro Wifi \& Bluetooth Meat Thermometer-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-65829?

CVE-2025-65829 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can execute on the device. ...

How severe is CVE-2025-65829?

CVE-2025-65829 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-65829?

Check the references section above for vendor advisories and patch information. Affected products include: Meatmeet Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware, Meatmeet Meatmeet Pro Wifi \& Bluetooth Meat Thermometer.