AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 are vulnerable to a Bluetooth Low Energy (BLE) denial-of-service condition. An unauthenticated attacker within BLE radio range can repeatedly initiate BLE connections, which interrupts keypad authentication input handling and repeatedly forces the device into lockout states, preventing legitimate users from unlocking the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Bluetooth exploit PoC for CVE-2025-34462, targeting a BLE-enabled smart padlock vulnerable to unauthenticated connection abuse and denial of service. The repository contains four files: a LICENSE, a README describing the vulnerability and usage, a requirements.txt listing the bleak dependency, and a single Python exploit script (poc.py). The exploit is not part of a larger framework. The main capability is sustained BLE-based denial of service. The script accepts a target MAC address via the -m argument, opens a BleakClient connection in an infinite loop, attempts to pair, and then continuously writes random 40-byte payloads to two hardcoded GATT characteristic UUIDs. This repeated connection/write behavior is intended to jam or interfere with the lock’s keypad authentication workflow, making the device unusable and forcing repeated lockout states. The code is offensive rather than diagnostic; it does not merely check for exposure. Notable fingerprintable values include a hardcoded sample BLE MAC address (CC:38:35:30:6F:83) and two targeted GATT characteristic UUIDs (00000001-0000-1001-8001-00805f9b07d0 and 00002a01-0000-1000-8000-00805f9b34fb). Operationally, the exploit requires physical proximity and BLE radio access, plus knowledge of the target MAC address. The PoC is somewhat rough: it mixes repeated connection attempts with continuous GATT writes, uses hardcoded characteristic UUIDs, and contains minor implementation issues such as calling client.connect() without await inside an async context manager. Even so, its intended purpose is clear: disrupt the target lock over BLE rather than achieve code execution or data theft.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.