CVE-2025-55297: Espressif Esp-Idf

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.

Affected products

  • Espressif Esp-Idf: before 5.0.9 (fixed in 5.0.9); from 5.1, before 5.1.6 (fixed in 5.1.6); from 5.2, before 5.3.3 (fixed in 5.3.3); from 5.4, before 5.4.1 (fixed in 5.4.1)

Published 2025-08-21. Last modified 2026-06-17.