PT-2026-48350 · Espressif · Esp-Idf

Published

2026-06-10

·

Updated

2026-06-10

·

CVE-2026-45328

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp tee component exposes secure-service wrappers in esp secure services.c and esp secure services iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.

Fix

Memory Corruption

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-45328

Affected Products

Esp-Idf