


Perceptive Security
SOC/SIEM Consultancy

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untr…
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 22:07:40
Source:
nvd.nist.gov
Mobile & IoT, Zero-Day Vulnerabilities
A heap-based buffer overflow vulnerability has been identified in schreibfaul1 ESP32-audioI2S version 3.4.5. The flaw exists in the URL path concatenation and encoding module, where the application splices untrusted extension paths and attacker-controlled query strings into a path buffer without validating the final string length before invoking urlencode. Remote attackers can craft oversized malicious URL paths and query strings to trigger an out-of-bounds heap write. Successful exploitation can lead to arbitrary code execution, information disclosure, service crash, or privilege escalation. The vulnerability is remotely exploitable and affects embedded IoT audio streaming devices based on ESP32 hardware. Given the IoT context, affected devices may be difficult to patch and could remain exposed for extended periods.
Technical details
Mitigation steps:
Affected products:
schreibfaul1 ESP32-audioI2S 3.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51267
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51267
https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/Audio.cpp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
