CVE-2025-12056
Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.
An unauthenticated attacker may arbitrarily reboot the device, effectively causing a denial of service (DoS).
November 18, 2025
This issue affects Shelly Pro 3EM below version v1.4.4
CVE-2025-12056
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
8.3
Until a software patch which fixes this issue is not released, it is highly recommended to segregate the device in a dedicated and protected network.
Gabriele Quagliarella of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

