CVE-2025-12888
HIGHXtensa-based ESP32 - Timing Side Channel
Title source: llmDescription
Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now turned on as the default for Xtensa.
Scores
CVSS v3
7.5
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-203
Status
published
Products (1)
wolfssl/wolfssl
5.8.2
Published
Nov 21, 2025
Tracked Since
Feb 18, 2026