CVE-2025-55297: Espressif Esp-Idf
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
Affected products
- Espressif Esp-Idf: before 5.0.9 (fixed in 5.0.9); from 5.1, before 5.1.6 (fixed in 5.1.6); from 5.2, before 5.3.3 (fixed in 5.3.3); from 5.4, before 5.4.1 (fixed in 5.4.1)
Published 2025-08-21. Last modified 2026-06-17.