CVE-2025-36939General(google / nest_wifi_point)

LOWCVSS 5.7 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nest_wifi_point
  • nest_wifi_point_firmware
  • nest_wifi_pro
  • nest_wifi_pro_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
nest_wifi_pointnest_wifi_point_firmwarenest_wifi_pronest_wifi_pro_firmwarenest_wifi_routernest_wifi_router_firmware

1 version affected across 6 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 2PoC Mentioned / Linked · 2026-08-25: 108-25
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-76070 - EXPLOIT CVE-2026-76071 - EXPLOIT CVE-2025-36939 CVE-2026-77995 CVE-2026-32559 ..🧵👇

    Post summary

    The post lists several CVE identifiers with minimal annotations, providing no technical or exploit details beyond labeling two as "EXPLOIT."

    1001070
    38 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2025-36939 [HIGH PRIORITY] 🔗 https://exploitgrid.net/cve/CVE-2025-36939

    Post summary

    The post references a high‑priority CVE and provides a link that presumably hosts a Proof of Concept, though no technical or exploit code details are disclosed.

    1000029
    38 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWgooglenest_wifi_point---
OSgooglenest_wifi_point_firmware3.78.518349--
HWgooglenest_wifi_pro---
OSgooglenest_wifi_pro_firmware3.78.518349--
HWgooglenest_wifi_router---
OSgooglenest_wifi_router_firmware3.78.518349--

Explore more