CVE Database
/

CVE-2025-66409

Back to search

CVE-2025-66409

Published: Dec 2, 2025

Modified: Dec 2, 2025

PUBLISHED

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VENDOR DEPENDENT command from a peer device can cause the Bluetooth stack to access memory before validating the command buffer length. This may lead to an out-of-bounds read, potentially exposing unintended memory content or causing unexpected behavior.

VendorProductVersions

espressif

esp-idf

affected
>= 5.5-beta1, <= 5.5.1
affected
>= 5.4-beta1, <= 5.4.3
affected
>= 5.3-beta1, <= 5.3.4
affected
>= 5.2-beta1, <= 5.2.6
affected
<= 5.1.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now