ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55297.json",
"cwe_ids": [
"CWE-120",
"CWE-131"
],
"cna_assigner": "GitHub_M"
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "5.0.9"
}
]
}{
"versions": [
{
"introduced": "5.1-beta1"
},
{
"fixed": "5.1.6"
}
]
}