
Work-in-progress PoC for CVE-2025-27840, an ESP32 Bluetooth vulnerability involving undocumented HCI commands enabling memory access and device control.
A Work-In-Progress for CVE-2025-27840
CVE-2025-27840 is a medium-severity vulnerability (CVSS 6.8) affecting Espressif ESP32 Bluetooth chips, which are integrated into over 1 billion IoT devices globally. The flaw involves 29 undocumented Host Controller Interface (HCI) commands that could enable unauthorized memory access and device control.
0xFC02 allows direct memory writingNote: While initially reported as a backdoor, Espressif clarified that exploitation requires privileged access, reducing immediate risk.