CVE-2023-25758

Source
https://cve.org/CVERecord?id=CVE-2023-25758
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25758.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-25758
Published
2023-02-14T00:00:00Z
Modified
2026-07-22T00:17:29.547704Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's position on an IP network). NOTE: the vendor states that "our hardware team has updated the security patch without anyone being affected."

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25758.json"
}
References

Affected packages

Git / github.com/onekeyhq/firmware

Affected ranges

Type
GIT
Repo
https://github.com/onekeyhq/firmware
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.0.0"
        },
        {
            "fixed": "2.10.0"
        }
    ]
}

Affected versions

bixin/v1.*
bixin/v1.9.4
bixin/v1.9.4.1
bixin/v1.9.5
bixin/v1.9.6
bixin/v1.9.7
bixin/v1.9.8
core/bl2.*
core/bl2.0.0
core/bl2.0.1
core/bl2.0.2
core/br2.*
core/br2.0.0
core/br2.0.1
core/v2.*
core/v2.0.10
core/v2.0.5
core/v2.0.6
core/v2.0.7
core/v2.0.8
core/v2.0.9
mini/v2.*
mini/v2.3.0
mini/v2.4.0
mini/v2.5.0
mini/v2.6.0
mini/v2.7.0
mini/v2.8.0
onekey/v2.*
onekey/v2.0.3
onekey/v2.0.4
python/v0.*
python/v0.11.3
python/v0.11.4
python/v0.11.5
python/v0.12.0
python/v0.12.1
python/v0.12.2
touch/v3.*
touch/v3.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25758.json"
vanir_signatures
[
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "line_hashes": [
                "51784189465652553163703033434400551020",
                "137713079017626693281912541753729148060",
                "309439914507890052333489217503242596917",
                "100783194833443195827103121086517599759"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2023-25758-1452d2fb",
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "legacy/firmware/cosmos/parser.c"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "line_hashes": [
                "330607054059673313056951312566764649628",
                "243354366214733855422636000732051924989",
                "23293312818053865596413501749663293488",
                "312761073974245759405252428500431721062"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2023-25758-5793a899",
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "legacy/firmware/fsm.c"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "length": 2224.0,
            "function_hash": "228642127853585338724087779827986729405"
        },
        "deprecated": false,
        "id": "CVE-2023-25758-69f60a7a",
        "signature_version": "v1",
        "signature_type": "Function",
        "target": {
            "function": "fsm_layoutAddress",
            "file": "legacy/firmware/fsm.c"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "length": 1851.0,
            "function_hash": "146779718868619953525353653486320340668"
        },
        "deprecated": false,
        "id": "CVE-2023-25758-71f32489",
        "signature_version": "v1",
        "signature_type": "Function",
        "target": {
            "function": "_readTxCommonParams",
            "file": "legacy/firmware/algo/parser_impl.c"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "line_hashes": [
                "79459999539857434306087329311297691959",
                "266258512386743563266164979397894856623",
                "270527081981999165369977590338174462806",
                "53393785337791385417833716063324375828",
                "90358660760153227646631038771462598245",
                "221346796322263998508657723670990509236",
                "155403512409487756200219723973913566346",
                "7150347536774373187018805654981517136"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2023-25758-8389a6a7",
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "legacy/firmware/algo/parser_impl.c"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "line_hashes": [
                "143643345648976854154956139811134177540",
                "72823957931599222521963778905569160428",
                "5116447039131181852385755563042066770",
                "73628806444196740286095207090782030113"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2023-25758-9dd62d21",
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "legacy/firmware/aptos.c"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "line_hashes": [
                "324592777450511399703732880887074872429",
                "187016370181013771080722289923122007578",
                "210192646834491445557900413253544535979",
                "101635963439344360106090128569511278974",
                "332057003952137025271827625139738034598",
                "232767041244318763159517542466339699822"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2023-25758-9e3ef6e8",
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "legacy/firmware/fsm_msg_coin.h"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "length": 2588.0,
            "function_hash": "331616924224958479176662249080649910637"
        },
        "deprecated": false,
        "id": "CVE-2023-25758-aeccb031",
        "signature_version": "v1",
        "signature_type": "Function",
        "target": {
            "function": "fsm_msgGetAddress",
            "file": "legacy/firmware/fsm_msg_coin.h"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "line_hashes": [
                "182783939741875285952175745382869571311",
                "315553901645990950304979705910290672883",
                "101469949840159349192643939775263794431",
                "4877954721286806764469322264336253401",
                "237706371748292505502963349528617927245",
                "178034559578642813796634370246700624175",
                "41726703022905817632157626206717057129",
                "94205813386909595559290515506414032223",
                "229166209114319010439729580687771222043",
                "208329613574052289646108331028785109961",
                "58876656644152184020645402096453316084",
                "52450496970319318553046831074326007652",
                "205122668907049488203585860343295228812",
                "219004660271937176182592686373403327712",
                "309823928776128593953331394371641870931",
                "218954905642938663508268546502925902349",
                "3005739200456736741442323175142472645",
                "228516956919516579364651742540059735013",
                "14136016230057906894368794121848943444",
                "206567186188096221443645222813423123349"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "id": "CVE-2023-25758-d092c297",
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "legacy/firmware/language.c"
        }
    },
    {
        "source": "https://github.com/onekeyhq/firmware/commit/2d2503dfa0b847301e99ef0644acbbf9cf9099a8",
        "digest": {
            "length": 2528.0,
            "function_hash": "151614550935159595861195210450798575966"
        },
        "deprecated": false,
        "id": "CVE-2023-25758-d0b9b5d9",
        "signature_version": "v1",
        "signature_type": "Function",
        "target": {
            "function": "parser_formatAmountItem",
            "file": "legacy/firmware/cosmos/parser.c"
        }
    }
]
vanir_signatures_modified
"2026-07-22T00:17:29Z"