CVE-2025-52471 | espressif esp-idf 5.1.6/5.2.5/5.3.3/5.4.1 ESP-NOW Protocol esp_now_register_recv_cb data_len integer underflow (GHSA-hqhh-cp47-fv5g / EUVD-2025-19059)
A vulnerability has been found in espressif esp-idf 5.1.6/5.2.5/5.3.3/5.4.1 and classified as very critical. Affected by this vulnerability is the function esp_now_register_recv_cb of the component ESP-NOW Protocol. The manipulation of the argument data_len leads to integer underflow.
This vulnerability is known as CVE-2025-52471. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.