CVE-2025-27840
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
- Published
- Mar 8, 2025
- Updated
- May 12, 2025
- Assigning CNA
- mitre
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:LLow · next 30 days
- Percentile
- 69.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
Sources
4Firmware for getting a power trace of the behavior of the bluetooth module on the ESP32 when the ESP32 is sent the undocumented hci bluetooth commands (CVE-2025-27840). Uses ESP-IDF v5.0.8 and v5.0.9.
Work-in-progress PoC for CVE-2025-27840, an ESP32 Bluetooth vulnerability involving undocumented HCI commands enabling memory access and device control.
Bitcoin Cryptanalysis: CVE-2025-27840 Vulnerability in ESP32 Microcontrollers Puts Billions of IoT Devices at Risk via Wi-Fi & Bluetooth
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.