Wednesday, September 16, 2026

Redmi Buds Vulnerability Could Allow Call Data Theft and Firmware Instability

Xiaomi’s Redmi Buds series faces critical security flaws that enable attackers to steal sensitive call data and crash devices without authentication.

Two newly disclosed vulnerabilities affect Redmi Buds 3 Pro through 6 Pro, allowing unauthenticated adversaries within Bluetooth range to access private phone numbers and trigger repeated denial of service conditions.

The vulnerabilities stem from improper handling of RFCOMM protocol mechanisms in the earbuds’ firmware. RFCOMM is a Bluetooth protocol layer that manages serial communication between paired devices.

Research from Carnegie Mellon University reveals that Redmi Buds maintain undocumented L2CAP and RFCOMM channels beyond the advertised Bluetooth profiles Hands-Free Profile (HFP), Advanced Audio Distribution Profile (A2DP), and Audio/Video Remote Control Profile (AVRCP) likely for legacy audio support or auxiliary services.

Critical Information Disclosure Flaw

CVE-2025-13834 exploits flawed bounds checking in the device’s RFCOMM TEST command handler.

When the control channel receives a TEST command with an inflated length field but empty payload, the faulty response mechanism returns uninitialized memory buffers containing up to 127 bytes of sensitive data.

Attackers can extract phone numbers of active call peers with a single packet, repeatedly triggering the flaw without user awareness.

The vulnerability closely mirrors the infamous Heartbleed bug (CVE-2014-0160), as both result from blind trust in packet length fields without adequate validation.

This memory disclosure represents a fundamental oversight in the earbuds’ firmware architecture and demonstrates how IoT protocol stacks remain susceptible to classical buffer over-read attacks.

CVE-2025-13328 describes a flooding vulnerability affecting RFCOMM channels.

Attackers can overwhelm the device’s processing queue by flooding the control channel with high-volume TEST commands or targeting Modem Status Command (MSC) signaling frames across HFP channels and undocumented Airoha auxiliary service channels.

Resource exhaustion triggers firmware crashes that forcibly disconnect all paired devices, requiring physical reset via the charging case for recovery.

Both vulnerabilities require no prior pairing, authentication, or user interaction. Attackers need only obtain the target device’s MAC address through basic Bluetooth scanning tools.

Exploitation range extends approximately twenty meters with standard equipment and no signal amplification, though physical barriers and Bluetooth version variations affect effective distance.

CVE IDVulnerability TypeAttack VectorImpact
CVE-2025-13834Information LeakRFCOMM TEST CommandCall data exposure, phone number theft
CVE-2025-13328Denial of ServiceRFCOMM FloodingFirmware crash, forced disconnection

Xiaomi has not responded to requests regarding remediation or mitigation strategies. No firmware patches are currently available.

Users should disable Bluetooth when earbuds are unused, particularly in public environments where attackers could exploit these flaws.

The vulnerabilities were discovered by researchers Choongin Lee, Jiwoong Ryu, and Heejo Lee, with documentation provided by the CERT Coordination Center.

These flaws highlight ongoing security challenges in consumer IoT devices where protocol implementations lack rigorous validation mechanisms.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates ancd Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google Search Makes It Harder to See Where a Link Really Goes Before You Click

Google has begun routing some organic Search result links...

Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

Phishing operators are increasingly shifting away from malware-laden attachments...

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in...

Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week

Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China...

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used...

Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop...

Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds

A threat actor exploited a critical pre-authentication remote code...

Related Articles

Recent News