CVE-2025-27840
CVE-2025-27840
Título es
CVE-2025-27840
Sáb, 08/03/2025 – 20:15
Tipo
CWE-912
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-27840
Descripción en
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
08/03/2025
08/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
Gravedad 3.1 (CVSS 3.1 Base Score)
6.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://github.com/TarlogicSecurity/Talks/blob/main/2025_RootedCon_BluetoothTools.pdf
https://reg.rootedcon.com/cfp/schedule/talk/5
https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/
https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/
https://x.com/pascal_gujer/status/1898442439704158276
Enviar en el boletín
Off
