CVE-2025-64342 Details
Description
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it receives a connection request containing an invalid Access Address (AA) of 0x00000000 or 0xFFFFFFFF, advertising may stop unexpectedly. In this case, the controller may incorrectly report a connection event to the host, which can cause the application layer to assume that the device has successfully established a connection. This issue has been fixed in versions 5.5.2, 5.4.3, 5.3.5, 5.2.6, and 5.1.7. At time of publication versions 5.5.2, 5.3.5, and 5.1.7 have not been released but are fixed respectively in commits 3b95b50, e3d7042, and 75967b5.
A vulnerability in the Bluetooth stack of the Espressif Internet of Things Development Framework (ESP-IDF) for the ESP32 chip has been identified. When the ESP32 is in advertising mode, it may receive connection requests with invalid Access Addresses (AA) of 0x00000000 or 0xFFFFFFFF. This can cause advertising to stop unexpectedly. The controller might then incorrectly report a connection event to the host, leading the application layer to believe a connection has been successfully established. This issue does not affect other Espressif chip families, such as ESP32-C, ESP32-S, and ESP32-H.
Users can upgrade to Espressif ESP-IDF versions 5.5.2, 5.4.3, 5.3.5, 5.2.6, or 5.1.7 to address this vulnerability. Instructions for updating can be found in the Espressif ESP-IDF documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 17, 2025CISA-ADP
Assessed Nov 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Espressif ESP-IDF | v5.5.1 (semver) v5.4.2 (semver) v5.3.4 (semver) v5.2.5 (semver) v5.1.6 (semver) |
CPE
Remediation
| |
| Espressif ESP32 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 17, 2025 | New CVE Received | [email protected] |
Volerion