CVE-2025-55297

EUVD-2025-25514
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
espressifesp-idf
𝑥
< 5.0.9
espressifesp-idf
5.1 ≤
𝑥
< 5.1.6
espressifesp-idf
5.2 ≤
𝑥
< 5.3.3
espressifesp-idf
5.4 ≤
𝑥
< 5.4.1
𝑥
= Vulnerable software versions