Espressif ESP32
cpe:2.3:h:espressif:esp32:*:*:*:*:*:*:*, +1 more
A vulnerability exists in Espressif ESP32 chips due to 29 undocumented HCI commands that can read and write memory, including flash memory. These commands, which are not documented by the manufacturer, could potentially be exploited to modify the chip's behavior or to conduct attacks on connected devices. The vulnerability arises from the Bluetooth Host Controller Interface (HCI), which allows commands to be sent from a host device to the Bluetooth controller.
Exploitation of these undocumented commands could lead to unauthorized modification of the Bluetooth controller's memory and behavior. This includes the possibility of writing persistent malware that survives device reboots, according to Tarlogic.
The vulnerability can be reproduced by sending vendor-specific HCI commands over a physical connection to the ESP32 chip, such as via USB or UART. This requires either physical access to the device or a prior compromise that allows direct communication with the Bluetooth controller. Once the commands are sent, they can be used to read and write memory, inject low-level Bluetooth packets, and spoof the device's MAC address.
Espressif has acknowledged the issue and plans to release a software update to remove the undocumented commands. Users are advised to update to the latest official firmware once it is available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.