Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-64342

23
FAUCET Score

CVE-2025-64342 describes a vulnerability in Espressif's ESP-IDF framework affecting ESP32 devices in advertising mode. Receiving a connection request with an invalid Access Address can cause advertising to stop and the device to incorrectly report a successful connection. This issue has a CVSS score of 6.9 (Medium), indicating a network-based attack with low complexity, potentially leading to a denial of service (availability impact). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Patches are available in ESP-IDF versions 5.5.2, 5.4.3, 5.3.5, 5.2.6, and 5.1.7.

Impacted Technologies

VendorProductVersion(s)CPE
EspressifEsp-Idf
< 5.1.7, >= 5.2-beta1, < 5.2.6, >= 5.3-beta1, < 5.3.5, >= 5.4-beta1, < 5.4.3, >= 5.5-beta1, < 5.5.2CNA affected

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 19th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / espressif/esp-idf/commit/309f031dd6b04de30c926a256508c65b0df95dfa
github.com / espressif/esp-idf/commit/3b95b50703cd3301a370cffaa1cc299b1941fe2a
github.com / espressif/esp-idf/commit/75967b578563ea7876dc215251cbb6d64bc9d768
github.com / espressif/esp-idf/commit/8ec541023684d33b498fa21c5b4724bce748aa7b
github.com / espressif/esp-idf/commit/bf66761962579f73aea682d1154b9c99b9d3d7dc
github.com / espressif/esp-idf/commit/e3d70429566ece1ef593d36aa4ebd320e0c95925
github.com / espressif/esp-idf/security/advisories/GHSA-8mg7-9qpg-p92v