CVE-2025-27840
MEDIUMDescription
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
Is your site exposed to CVE-2025-27840?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| espressif | esp32_firmware |
| espressif | esp32 |
References
Exploits
Other References
Frequently Asked Questions
What is CVE-2025-27840? +
How severe is CVE-2025-27840? +
What products are affected by CVE-2025-27840? +
How do I check if I'm vulnerable to CVE-2025-27840? +
Related Vulnerabilities
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not …
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized …
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, …
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 …
Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located …
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets …