logo

Bluetooth “Heartbleed” and DoS Flaws Found in Xiaomi Redmi Buds, No Patch

ID: 14791fef-c135-5420-beb9-de7562ba1855

STIX ID: report--14791fef-c135-5420-beb9-de7562ba1855

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers disclosed two critical vulnerabilities in Xiaomi Redmi Buds 3 Pro through 6 Pro: CVE-2025-13834 is an unauthenticated information-leak (similar to Heartbleed) that can return up to 127 bytes of uninitialized memory (potentially exposing call peer phone numbers), and CVE-2025-13328 is a flooding-based DoS that crashes firmware and severs active connections; both can be exploited from Bluetooth range without pairing, no patch is available, and the short-term mitigation is to disable Bluetooth when not in use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.