Back to overview

CVE-2026-65058

MEDIUM
5.3
CVSS 3.1
Description
Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c.

Metadata

CVE ID
CVE-2026-65058
State
PUBLISHED
Assigner
cisa-cg
Reserved
2026-07-21 14:35 UTC
Published
2026-07-21 20:13 UTC
Last updated
2026-07-21 20:13 UTC
Primary CWE
CWE-358
CWE-358 Improperly Implemented Security Check for Standard
Vendor / Product
Trezor / Safe 3
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products (3)
VendorProductPlatformVersions
Trezor Safe 3 0 < 70c9b0c, 70c9b0c
Trezor Safe 5 0 < 70c9b0c, 70c9b0c
Trezor Safe 7 0 < 70c9b0c, 70c9b0c
Weakness (CWE)
CWESourceDescription
CWE-358 cna CWE-358 Improperly Implemented Security Check for Standard
CVSS scores (2)
ScoreSeverityVersionSourceVector
5.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Back to overview