CVE-2025-55297 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
- 🔗 github.com/espressif/esp-idf/security/advisories/GHS…
- 🔗 github.com/espressif/esp-idf/commit/12b7a9e6d78012ab…
- 🔗 github.com/espressif/esp-idf/commit/3fc6c93936077cb1…
- 🔗 github.com/espressif/esp-idf/commit/5f93ec3b11b61154…
- 🔗 github.com/espressif/esp-idf/commit/9cb7206d4ae8fd8f…
- 🔗 github.com/espressif/esp-idf/commit/abc18e93eb3500db…
- 🔗 github.com/espressif/esp-idf/commit/b1657d9dd4d0e48e…
- 🔗 github.com/espressif/esp-idf/commit/bf50c0c197af3099…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-13 | 2026-09-26 |
|---|---|---|
| ≥90 % | 0 | 497 |
| ≥50 % | 0 | 1467 |
| ≥10 % | 0 | 1 |
| <10 % | 300 | 0 |
CVE-2025-55297 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is
Noch keine Analyse zu CVE-2025-55297
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.