CVE-2025-55297

HIGH

espressif/esp-idf < 5.0.9 - Buffer Overflow in BluFi Example

Title source: llm
STIX 2.1

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.

References (13)

Core 13
Core References

Scores

CVSS v3 8.8
EPSS 0.0032
EPSS Percentile 23.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-131 CWE-120
Status published
Products (1)
espressif/esp-idf < 5.0.9
Published Aug 21, 2025
Tracked Since Feb 18, 2026