top of page
perceptive_background_267k.jpg

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untr…

Published:

28 July 2026 at 00:00:00

Alert date:

28 July 2026 at 22:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Zero-Day Vulnerabilities

A heap-based buffer overflow vulnerability has been identified in schreibfaul1 ESP32-audioI2S version 3.4.5. The flaw exists in the URL path concatenation and encoding module, where the application splices untrusted extension paths and attacker-controlled query strings into a path buffer without validating the final string length before invoking urlencode. Remote attackers can craft oversized malicious URL paths and query strings to trigger an out-of-bounds heap write. Successful exploitation can lead to arbitrary code execution, information disclosure, service crash, or privilege escalation. The vulnerability is remotely exploitable and affects embedded IoT audio streaming devices based on ESP32 hardware. Given the IoT context, affected devices may be difficult to patch and could remain exposed for extended periods.

Technical details

Mitigation steps:

Affected products:

schreibfaul1 ESP32-audioI2S 3.4.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page