K. Reid Wightman :verified: 🌻 :donor: :clippy: on Nostr: That ESP32 thing has a CVE: CVE-2025-27840: . And, pretty much everything all of the ...
That ESP32 thing has a CVE: CVE-2025-27840:
https://nvd.nist.gov/vuln/detail/CVE-2025-27840 .
And, pretty much everything all of the well-known infosec people have been saying is correct: physical access required (or, high privileges and high attack complexity; the score is kinda 'wrong' in some sense because it is combining two exploitation vectors but I think it gets across the point: this is not wormable and is not exploitable via wireless, at least not on its own. and if your threat model allows for physical access but still treats this as a big deal somehow, go home, your threat model is drunk).
Published at
2025-03-09 04:03:24 UTCEvent JSON
{
"id": "fe00bda30d281b2414cf17bd8440d5e6f71836e119851fa7451b3b51a74ee07f",
"pubkey": "925bf02d5e02f91b698b83ce48c263bbff783a3a844c983ae2b8ce8beb2a9609",
"created_at": 1741493004,
"kind": 1,
"tags": [
[
"proxy",
"https://infosec.exchange/@reverseics/114130485558192909",
"web"
],
[
"proxy",
"https://infosec.exchange/users/reverseics/statuses/114130485558192909",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://infosec.exchange/users/reverseics/statuses/114130485558192909",
"pink.momostr"
],
[
"-"
]
],
"content": "That ESP32 thing has a CVE: CVE-2025-27840: https://nvd.nist.gov/vuln/detail/CVE-2025-27840 . \n\nAnd, pretty much everything all of the well-known infosec people have been saying is correct: physical access required (or, high privileges and high attack complexity; the score is kinda 'wrong' in some sense because it is combining two exploitation vectors but I think it gets across the point: this is not wormable and is not exploitable via wireless, at least not on its own. and if your threat model allows for physical access but still treats this as a big deal somehow, go home, your threat model is drunk).",
"sig": "c6a522ed4db8a730f506d6d9aaa257563ca04f00bb48648e4cf209096cbfb1fb8d13ff03d47dcd2cb2343855f227903916ee74ef02e09d5ab441d5d5c29ba248"
}