CVE-2025-27840
MEDIUMEspressif ESP32 - Info Disclosure
Title source: llmDescription
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
Exploits (3)
nomisec
WRITEUP
11 stars
by demining · poc
https://github.com/demining/Bluetooth-Attacks-CVE-2025-27840
References (15)
Scores
CVSS v3
6.8
EPSS
0.0058
EPSS Percentile
69.0%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-912
Status
published
Products (1)
espressif/esp32_firmware
Published
Mar 08, 2025
Tracked Since
Feb 18, 2026