ESP32 UART Download Mode Vulnerability in Meatmeet Pro BBQ Thermometer

Vulnerability

A vulnerability exists in the Meatmeet Pro BBQ Thermometer, specifically in version 1.0.34.4, due to the ESP32 chip's UART download mode being enabled. This allows an adversary with physical access to the device to dump the flash memory and extract sensitive information, such as Wi-Fi network details from the NVS partition. Furthermore, the vulnerability enables the adversary to reflash the device with custom firmware that could include malicious modifications.

Impact

Exploitation of this vulnerability could lead to unauthorized access to the victim's Wi-Fi network and the execution of malicious code on the Meatmeet device.

Reproduction

The vulnerability can be reproduced by disassembling the Meatmeet Pro BBQ Thermometer to access the internal circuit board. Once the device is disassembled, a USB-UART adapter can be used to connect to the device over UART. After putting the device into download mode, the UART log will indicate that the device is ready to accept commands. At this point, the flash memory can be dumped using a tool like 'esptool', and the extracted data can be analyzed for sensitive information such as Wi-Fi credentials.

Added: Dec 10, 2025, 9:26 PM
Updated: Dec 10, 2025, 9:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.