logo

ESP32 BluFi Vulnerabilities Enable Code Execution

ID: 8db80b96-8be5-5b52-a9ca-8f3e8ded63b0

STIX ID: report--8db80b96-8be5-5b52-a9ca-8f3e8ded63b0

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-08-03

...
...

NCC Group discovered multiple memory corruption and cryptographic flaws in the ESP32 BluFi reference application that could allow remote arbitrary code execution over Bluetooth and disclosure of WiFi credentials; patches were produced, vendor communications and a CVE (CVE-2025-55297) were recorded, and recommendations/patches are available in the official esp-idf repository.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.