CVE-2025-27840 describes a medium-severity vulnerability affecting Espressif ESP32 chips and firmware, where 29 hidden HCI commands, including a memory write function (0xFC02), are present. This physical access vulnerability (AV:P) requires high privileges (PR:H) but has high confidentiality and integrity impacts (C:H/I:H). While not currently in CISA KEV or having public exploit code, it has garnered significant community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:espressif:esp32_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.