CVE-2025-55297
EUVD-2025-2551421.08.2025, 15:15
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| espressif | esp-idf | 𝑥 < 5.0.9 |
| espressif | esp-idf | 5.1 ≤ 𝑥 < 5.1.6 |
| espressif | esp-idf | 5.2 ≤ 𝑥 < 5.3.3 |
| espressif | esp-idf | 5.4 ≤ 𝑥 < 5.4.1 |
𝑥
= Vulnerable software versions
References