216.73.217.24

CVE-2025-66409

· Published 02/12/2025 19:15 · Modified 04/12/2025 17:15

Labels: CVE-2025-66409 2025-12-02CVE-2025-66409CWE-125[email protected]

Essential information

Published
02/12/2025 19:15
Modified
04/12/2025 17:15
Author
Creator
CVSS
2.7 LOW (v3) 2.7 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VENDOR DEPENDENT command from a peer device can cause the Bluetooth stack to access memory before validating the command buffer length. This may lead to an out-of-bounds read, potentially exposing unintended memory content or causing unexpected behavior.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References