Medium severity6.8NVD Advisory· Published Mar 8, 2025· Updated Jun 17, 2026
CVE-2025-27840
CVE-2025-27840
Description
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:espressif:esp32_firmware:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- darkmentor.com/blog/esp32_non-backdoor/nvdExploitTechnical DescriptionThird Party Advisory
- www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/nvdExploitPress/Media Coverage
- www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices/nvdExploitPress/Media Coverage
- cheriot.org/auditing/backdoor/2025/03/09/no-esp32-style-backdoor.htmlnvdTechnical DescriptionThird Party Advisory
- flyingpenguin.comnvdTechnical DescriptionThird Party Advisory
- github.com/TarlogicSecurity/Talks/blob/main/2025_RootedCon_BluetoothTools.pdfnvdThird Party Advisory
- reg.rootedcon.com/cfp/schedule/talk/5nvdThird Party Advisory
- www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/nvdThird Party Advisory
- x.com/pascal_gujer/status/1898442439704158276nvdThird Party Advisory
- news.ycombinator.com/itemnvdIssue Tracking
- news.ycombinator.com/itemnvdIssue Tracking
- www.espressif.com/en/news/Response_ESP32_BluetoothnvdPress/Media Coverage
News mentions
0No linked articles in our index yet.