Known Vulnerabilities for Nano S by Ledger
Listed below are 2 of the newest known vulnerabilities associated with "Nano S" by "Ledger".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Ledger Nano S
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-25869 json | MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The applicat... | Not Provided | 2026-02-11 | 2026-07-14 |
| CVE-2026-25868 json | MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir pa... | Not Provided | 2026-02-11 | 2026-07-14 |
| CVE-2026-15043 json | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-6390 json | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one trigg... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2025-15645 json | Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to mis... | Not Provided | 2026-05-19 | 2026-07-14 |
| CVE-2025-5085 json | The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2024-41624 json | Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspeci... | Not Provided | 2024-07-29 | 2026-07-09 |
| CVE-2020-6861 json | A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker t... | 5.5 - MEDIUM | 2020-05-06 | 2021-07-21 |
| CVE-2019-14354 json | On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each r... | 2.4 - LOW | 2019-08-10 | 2021-07-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ledger | Nano S | - |