UART Download Mode Vulnerability in ESP32 Chip by Espressif
CVE-2025-65821
What is CVE-2025-65821?
The ESP32 chip's UART download mode remains enabled, posing a significant risk as adversaries can exploit this feature to extract sensitive information stored within the device's flash memory. This includes access to credentials of current and previous Wi-Fi networks from the non-volatile storage (NVS) partition. Furthermore, attackers can reflash the device with malicious firmware, potentially compromising device integrity and functionality. Users are advised to implement strict security measures to disable UART download mode and protect sensitive data from unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
