Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-55297

28
FAUCET Score

CVE-2025-55297 describes memory overflow vulnerabilities within the BluFi example of Espressif's ESP-IDF, affecting versions prior to 5.4.1, 5.3.3, 5.1.6, and 5.0.9. With a CVSS score of 8.8 (HIGH), this vulnerability allows an unauthenticated attacker on the adjacent network to achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.0.9CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*
>= 5.1, < 5.1.6CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*
>= 5.2, < 5.3.3CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*
>= 5.4, < 5.4.1CPE matchmatch criteria
cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.2MEDIUM

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
ADJACENT
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 25th percentile among its peer group of 1,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / espressif/esp-idf/commit/12b7a9e6d78012ab9184b7ccdb5524364bf7e345
Patch
github.com / espressif/esp-idf/commit/3fc6c93936077cb1659e1f0e0268e62cf6423e9d
Patch
github.com / espressif/esp-idf/commit/5f93ec3b11b6115475c34de57093b3672d594e8f
Patch
github.com / espressif/esp-idf/commit/9cb7206d4ae8fd8f4296cd57d6c78a1656f42efa
Patch
github.com / espressif/esp-idf/commit/abc18e93eb3500dbec74c3e589671ef82c8b3919
Patch
github.com / espressif/esp-idf/commit/b1657d9dd4d0e48ed25e02cb8fe8413f479a2a84
Patch
github.com / espressif/esp-idf/commit/bf50c0c197af30990026c8f8286298d2aa5a3c99
Patch
github.com / espressif/esp-idf/commit/cb6929a2e6f2ff130b742332dc15eb23006c7cc9
Patch
github.com / espressif/esp-idf/commit/cc00e9f2fc4f7e8fbaff27851b4a8b45fa483501
Patch
github.com / espressif/esp-idf/commit/e65cf7ea2a2be52219ec9d4efc44aed5e490e91c
Patch
github.com / espressif/esp-idf/commit/f40aa9c587a8e570dfde2e6330382dcd170d5a5d
Patch
github.com / espressif/esp-idf/commit/f77da0d5b5382635c99e6708551b73802ad1213d
Patch
github.com / espressif/esp-idf/security/advisories/GHSA-9w88-r2vm-qfc4
Vendor Advisory