Description
As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to reflash the device with their own firmware which may contain malicious modifications.
References (2)
Core 2
Core References
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
10.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1191
Status
published
Products (1)
meatmeet/meatmeet_pro_wifi_\&_bluetooth_meat_thermometer_firmware
1.0.34.4
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026