PT-2025-10465 · Espressif · Espressif Esp32
Rjmunro
·
Published
2025-03-08
·
Updated
2026-04-17
·
CVE-2025-27840
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Espressif ESP32 (affected versions not specified)
Description
The Espressif ESP32 chip contains 29 hidden HCI commands, such as 0xFC02 (Write memory), which can be used for cyberattacks. These commands can be exploited to impersonate trusted devices, gain unauthorized access to data, pivot to other devices on the network, and potentially establish long-term persistence. The issue affects over a billion devices worldwide, including IoT devices, and highlights the need for better security audits.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Hidden Functionality
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Espressif Esp32