CVE-2019-12588: Espressif Arduino ESP8266
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association responses, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
Affected products
- Espressif Arduino ESP8266: up to and including 2.5.2
- Espressif ESP8266 Nonos SDK: from 2.2.0, up to and including 3.1.0
Published 2019-09-04. Last modified 2026-06-17.