CVE-2025-66409: ESF-IDF has an Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VENDOR DEPENDENT command from a peer device can cause the Bluetooth stack to access memory before validating the command buffer length. This may lead to an out-of-bounds read, potentially exposing unintended memory content or causing unexpected behavior.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66409?
CVE-2025-66409 is classified as a medium severity vulnerability.
How do I fix CVE-2025-66409?
To mitigate CVE-2025-66409, you should update your Espressif ESF-IDF to version 5.5.1 or later.
What systems are affected by CVE-2025-66409?
CVE-2025-66409 affects Espressif ESF-IDF versions up to 5.5.1.
What happens if CVE-2025-66409 is exploited?
Exploitation of CVE-2025-66409 can lead to unauthorized access to memory, potentially compromising the Bluetooth stack.
Is there a workaround for CVE-2025-66409?
Currently, the best workaround for CVE-2025-66409 is to disable AVRCP if not needed until an update is applied.