PT-2025-50496 · Espressif · Esp32

Published

2025-12-10

·

Updated

2026-04-15

·

CVE-2025-65821

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ESP32 (affected versions not specified)
Description An enabled UART download mode on the ESP32 chip allows an attacker to extract sensitive data from the flash memory, including Wi-Fi network details stored in the NVS partition. This access also enables reflashing the device with potentially malicious firmware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-65821

Affected Products

Esp32