CVE-2025-56365Csa-iot · Matter
Vulnerability data via NVD (ingested)
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as valid due to missing checks in CodegenDataModelProvider::Invoke. This causes a VerifyOrDie failure in ProcessCommandDataIB and results in a crash (SIGABRT). The issue has been acknowledged and fixed in a later revision (PR #37207).
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2025-56365product:"Csa-iot Matter"http.html:"Matter"More intel sources (5)
vuln:CVE-2025-56365vulnerabilities.cve_id: CVE-2025-56365CVE-2025-56365CVE-2025-56365"CVE-2025-56365" exploit -site:nvd.nist.gov