← back
CVE-2025-65821highCWE-1191

CVE-2025-65821

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
In short

The ESP32 chip has an enabled UART download mode that lets attackers extract sensitive data like Wi-Fi credentials from the device's flash memory and replace the firmware with malicious code.

Technical detail

UART download mode is accessible on the ESP32 without authentication, allowing an attacker with physical access to dump flash memory contents (including NVS partition with stored credentials) and reflash arbitrary firmware. This provides complete device compromise with no mitigations in place.

Summary generated and translated by AI from the official description.
As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to reflash the device with their own firmware which may contain malicious modifications.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a