CVE-2025-55297: ESF-IDF BluFi Example Memory Overflow Vulnerability
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55297?
CVE-2025-55297 has been classified as a high severity vulnerability due to memory overflows that could lead to potential exploits.
How do I fix CVE-2025-55297?
To resolve CVE-2025-55297, upgrade to ESP-IDF versions 5.4.1, 5.3.3, 5.1.6, or 5.0.9.
What areas are impacted by CVE-2025-55297?
CVE-2025-55297 specifically affects Wi-Fi credential handling and the Diffie–Hellman key exchange mechanisms.
What software is affected by CVE-2025-55297?
CVE-2025-55297 affects the Espressif ESP-IDF framework versions prior to 5.4.1.
Is there a specific example that illustrates CVE-2025-55297?
Yes, the BluFi example included in the ESP-IDF is specifically vulnerable to the issues highlighted in CVE-2025-55297.