CVE-2025-27840False Positive(espressif / esp32)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • esp32
  • esp32_firmware

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • False Positive: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
esp32esp32_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-28: 1Mentions · 2026-08-03: 1Mentions · 2026-08-19: 1Technical Details · 2026-08-03: 103-2808-0308-19
Signal classification2 categories
False Positive
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-281
False Positive1
2026-08-031
Disclosure1
2026-08-191
False Positive1
Full discourse3 posts
  • 2140.wtf NOSTR APP@2140wtf
    False Positive

    @stephanlivera @Blockstream @BlockstreamJade I have noticed some FUD is resurfacing about that vuln in esp32 chip so just to iterate JADE IS SAFU! https://btctimes.com/blockstreams-jade-wallet-deemed-unaffected-by-esp32-vulnerability https://www.cve.org/CVERecord?id=CVE-2025-27840 https://nvd.nist.gov/vuln/detail/cve-2025-27840

    Post summary

    The post counters FUD about the esp32 vulnerability, asserting that Blockstream’s Jade wallet is unaffected.

    10020158
    1.5K followersView on X
  • Douglas H🅰️yse 🧇@Factualman6404
    Disclosure

    @ricardoXMR @SD_HODL I was disappointed to see this og of big dogs Adam back and his hardware wallet have a issue discovered. ESP32 Chip Random Number Generator Flaw (April 2025)The Issue: A hardware flaw registered as CVE-2025-27840 impacted the ESP32 chip used inside Jade devices.

    Post summary

    A hardware random‑number‑generator flaw was discovered in the ESP32 chip used in Jade hardware wallets, identified as CVE‑2025‑27840.

    0000068
    1.3K followersView on X
  • @Anti_Ch_PC@Anti_Ch_PCgc
    False Positive

    https://note.com/bruteforce_diy/n/n2b6d9554c963 世界10億台超のIoT機器に使われる中国製チップ「ESP32」にバックドア疑惑が浮上しました(CVE-2025-27840)。メーカーは悪意ある実装ではないと説明していますが、スマート家電の製造元を一度確認してみてもいいかもしれませんよ。#セキュリティ

    Post summary

    The post reports a backdoor suspicion for the ESP32 chip (CVE‑2025‑27840) but cites the manufacturer’s denial of malicious intent, implying the CVE may be a false positive.

    00000220
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWespressifesp32---
OSespressifesp32_firmware---

Explore more