Skip to content

CVE-2025-27840: Are our devices at risk? #7699

Answered by gfwilliams
rjmunro asked this question in ESP32
Discussion options

You must be logged in to vote

Just read the first paragraph of https://www.flyingpenguin.com/?p=67838 (first link from https://nvd.nist.gov/vuln/detail/CVE-2025-27840 )

There is no issue whatsoever - this is just undocumented functionality that's no use to external hackers. If you can run arbitrary code on the ESP32 then yes you can use them, but if a hacker can run arbitrary code then honestly you've got more to worry about than this!

IMO it just makes a mockery of the vulnerability reporting system (I can't believe the CVE even links to this post now!). It's extremely clickbait reporting by bleepingcomputer too - note if you look now they've had to remove the word 'backdoor' from the article.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@xyzzy42
Comment options

Answer selected by gfwilliams
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
ESP32
Labels
None yet
3 participants