element14 Community
element14 Community
    Register Log In
  • Site
  • Search
  • Log In Register
  • About Us
  • Community Hub
    Community Hub
    • What's New on element14
    • Feedback and Support
    • Benefits of Membership
    • Personal Blogs
    • Members Area
    • Achievement Levels
  • Learn
    Learn
    • Ask an Expert
    • eBooks
    • element14 presents
    • Learning Center
    • Tech Spotlight
    • STEM Academy
    • Webinars, Training and Events
    • Learning Groups
  • Technologies
    Technologies
    • 3D Printing
    • FPGA
    • Industrial Automation
    • Internet of Things
    • Power & Energy
    • Sensors
    • Technology Groups
  • Challenges & Projects
    Challenges & Projects
    • Design Challenges
    • element14 presents Projects
    • Project14
    • Arduino Projects
    • Raspberry Pi Projects
    • Project Groups
  • Products
    Products
    • Arduino
    • Avnet Boards Community
    • Dev Tools
    • Manufacturers
    • Multicomp Pro
    • Product Groups
    • Raspberry Pi
    • RoadTests & Reviews
  • Store
    Store
    • Visit Your Store
    • Choose another store...
      • Europe
      •  Austria (German)
      •  Belgium (Dutch, French)
      •  Bulgaria (Bulgarian)
      •  Czech Republic (Czech)
      •  Denmark (Danish)
      •  Estonia (Estonian)
      •  Finland (Finnish)
      •  France (French)
      •  Germany (German)
      •  Hungary (Hungarian)
      •  Ireland
      •  Israel
      •  Italy (Italian)
      •  Latvia (Latvian)
      •  
      •  Lithuania (Lithuanian)
      •  Netherlands (Dutch)
      •  Norway (Norwegian)
      •  Poland (Polish)
      •  Portugal (Portuguese)
      •  Romania (Romanian)
      •  Russia (Russian)
      •  Slovakia (Slovak)
      •  Slovenia (Slovenian)
      •  Spain (Spanish)
      •  Sweden (Swedish)
      •  Switzerland(German, French)
      •  Turkey (Turkish)
      •  United Kingdom
      • Asia Pacific
      •  Australia
      •  China
      •  Hong Kong
      •  India
      •  Korea (Korean)
      •  Malaysia
      •  New Zealand
      •  Philippines
      •  Singapore
      •  Taiwan
      •  Thailand (Thai)
      • Americas
      •  Brazil (Portuguese)
      •  Canada
      •  Mexico (Spanish)
      •  United States
      Can't find the country/region you're looking for? Visit our export site or find a local distributor.
  • Translate
  • Profile
  • Settings
Internet of Things
  • Technologies
  • More
Internet of Things
Forum Can the ESP32 be trusted? Undocumented "backdoor" found in popular microcontroller
  • Blog
  • Forum
  • Documents
  • Quiz
  • Events
  • Polls
  • Members
  • Mentions
  • Sub-Groups
  • Tags
  • More
  • Cancel
  • New
Join Internet of Things to participate - click to join for free!
Actions
  • Share
  • More
  • Cancel
Forum Thread Details
  • Replies 9 replies
  • Subscribers 502 subscribers
  • Views 2032 views
  • Users 0 members are here
  • esp32
  • security
  • bluetooth attacks
  • esp32 backdoor
  • cybersecurity
Related

Can the ESP32 be trusted? Undocumented "backdoor" found in popular microcontroller

cstanton
cstanton 6 months ago

As per https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/ : 

"At RootedCON, the Tarlogic Innovation team presents research revealing undocumented commands in the ESP32 microchip, present in millions of smart devices with Bluetooth

The cybersecurity company has designed a unique tool to perform security audits of Bluetooth devices on any operating system
Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices. Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls."

bluetooth vulnerability

(source: https://x.com/Tarlogic/status/1897584096135581721)

I always suspected that Bluetooth was vulnerable in some manner, but for the ESP32 to have something shady about it is astonishing. If you're interested in cyber security you should check out Tarlogic's github repositories and X feed.

  • Sign in to reply
  • Cancel

Top Replies

  • embeddedguy
    embeddedguy 6 months ago in reply to embeddedguy +8
    finally there is a clarification from Espressif today with press release. The key point they said is that these commands cannot be executed remotely over Bletooth or WiFi. Espressif’s Response to Claimed…
  • JWx
    JWx 6 months ago +7
    After quick examination it seems less severe than hyped: If this is that one: CVE-2025-27840 "Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory)." they have discovered…
  • BigG
    BigG 6 months ago in reply to embeddedguy +3
    Further details provided on Espressif's developer portal: https://developer.espressif.com/blog/2025/03/esp32-bluetooth-clearing-the-air/
Parents
  • embeddedguy
    embeddedguy 6 months ago

    Depends what level of PSA certification you have for your chip. For example, the normal esp32 device does not have any certificate. But ESP32-C6 is PSA level 2 certified. Hence more safety for code and data also safety from attacks to corrupt the firmware using OTA etc.

    Sometimes these kinds of news are hyped and what impact it could make to end device is a question to be asked.!

    • Cancel
    • Vote Up +2 Vote Down
    • Sign in to reply
    • Cancel
  • embeddedguy
    embeddedguy 6 months ago in reply to embeddedguy

    finally there is a clarification from Espressif today with press release.

    The key point they said is that these commands cannot be executed remotely over Bletooth or WiFi.

    Espressif’s Response to Claimed Backdoor and Undocumented Commands in ESP32 Bluetooth Stack | Espressif Systems

    • Cancel
    • Vote Up +8 Vote Down
    • Sign in to reply
    • Cancel
  • BigG
    BigG 6 months ago in reply to embeddedguy

    Further details provided on Espressif's developer portal: https://developer.espressif.com/blog/2025/03/esp32-bluetooth-clearing-the-air/

    • Cancel
    • Vote Up +3 Vote Down
    • Sign in to reply
    • Cancel
Reply
  • BigG
    BigG 6 months ago in reply to embeddedguy

    Further details provided on Espressif's developer portal: https://developer.espressif.com/blog/2025/03/esp32-bluetooth-clearing-the-air/

    • Cancel
    • Vote Up +3 Vote Down
    • Sign in to reply
    • Cancel
Children
No Data
element14 Community

element14 is the first online community specifically for engineers. Connect with your peers and get expert answers to your questions.

  • Members
  • Learn
  • Technologies
  • Challenges & Projects
  • Products
  • Store
  • About Us
  • Feedback & Support
  • FAQs
  • Terms of Use
  • Privacy Policy
  • Legal and Copyright Notices
  • Sitemap
  • Cookies

An Avnet Company © 2025 Premier Farnell Limited. All Rights Reserved.

Premier Farnell Ltd, registered in England and Wales (no 00876412), registered office: Farnell House, Forge Lane, Leeds LS12 2NE.

ICP 备案号 10220084.

Follow element14

  • X
  • Facebook
  • linkedin
  • YouTube