VYPR
Critical severity9.1NVD Advisory· Published Dec 2, 2025· Updated Jun 17, 2026

CVE-2025-66409

CVE-2025-66409

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VENDOR DEPENDENT command from a peer device can cause the Bluetooth stack to access memory before validating the command buffer length. This may lead to an out-of-bounds read, potentially exposing unintended memory content or causing unexpected behavior.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Espressif/Esp Idf3 versions
    cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:espressif:esp-idf:*:*:*:*:*:*:*:*range: <=5.1.6
    • (no CPE)range: 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier
    • (no CPE)range: >= 5.5-beta1, <= 5.5.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.