#VU122301 Integer underflow in ESP-IDF - CVE-2026-25532
Published: February 4, 2026
ESP-IDF
Espressif Systems
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer underflow in the WPS Enrollee implementation. A remote attacker on the local network can send a specially crafted request to the affected application, trigger integer underflow and cause a denial of service condition on the target system.