CVE-2025-12888

HIGH

Xtensa-based ESP32 - Timing Side Channel

Title source: llm

Description

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-203
Status published
Products (1)
wolfssl/wolfssl 5.8.2
Published Nov 21, 2025
Tracked Since Feb 18, 2026