Medium severity6.5NVD Advisory· Published Sep 7, 2021· Updated Jun 17, 2026
CVE-2021-28135
CVE-2021-28135
Description
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Espressif/ESP-IDFdescription
Patches
Vulnerability mechanics
References
2- dl.packetstormsecurity.net/papers/general/braktooth.pdfnvdBroken Link
- www.espressif.com/en/products/socs/esp32nvdProduct
News mentions
0No linked articles in our index yet.