CVE Vulnerabilities

CVE-2025-27840

Hidden Functionality

Published: Mar 08, 2025 | Modified: Mar 12, 2025
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).

Weakness

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product’s users or administrators.

Affected Software

Name Vendor Start Version End Version
Esp32_firmware Espressif - (including) - (including)

Potential Mitigations

References