CVE-2025-66409
Published: Dec 2, 2025
Modified: Dec 2, 2025
Description
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VENDOR DEPENDENT command from a peer device can cause the Bluetooth stack to access memory before validating the command buffer length. This may lead to an out-of-bounds read, potentially exposing unintended memory content or causing unexpected behavior.
| Vendor | Product | Versions |
|---|---|---|
espressif | esp-idf | affected >= 5.5-beta1, <= 5.5.1affected >= 5.4-beta1, <= 5.4.3affected >= 5.3-beta1, <= 5.3.4affected >= 5.2-beta1, <= 5.2.6affected <= 5.1.6 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now