ESP32 BluFi Vulnerabilities Enable Code Execution
ID: 8db80b96-8be5-5b52-a9ca-8f3e8ded63b0
STIX ID: report--8db80b96-8be5-5b52-a9ca-8f3e8ded63b0
Feed Name: NCC Research
Threat Score
NCC Group discovered multiple memory corruption and cryptographic flaws in the ESP32 BluFi reference application that could allow remote arbitrary code execution over Bluetooth and disclosure of WiFi credentials; patches were produced, vendor communications and a CVE (CVE-2025-55297) were recorded, and recommendations/patches are available in the official esp-idf repository.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
