CVE-2026-14297

EUVD-2026-72299
A buffer overflow in the Bluetooth Continuous Glucose
     Monitoring Service (CGMS) Record Access Control Point (RACP) write handler
     allows an authenticated BLE peer to overflow a 20-byte static buffer into
     adjacent BSS memory. The exploitable impact cannot be predetermined - it
     is entirely dependent on the linker-assigned BSS layout of the specific
     firmware build, which may vary.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.99%