UART Download Mode Vulnerability in ESP32 Chip by Espressif
CVE-2025-65821

7.5HIGH

Key Information:

Vendor

Espressif

Vendor
CVE Published:
10 December 2025

What is CVE-2025-65821?

The ESP32 chip's UART download mode remains enabled, posing a significant risk as adversaries can exploit this feature to extract sensitive information stored within the device's flash memory. This includes access to credentials of current and previous Wi-Fi networks from the non-volatile storage (NVS) partition. Furthermore, attackers can reflash the device with malicious firmware, potentially compromising device integrity and functionality. Users are advised to implement strict security measures to disable UART download mode and protect sensitive data from unauthorized access.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.