Back to overview

CVE-2026-51273

HIGH Exploitation: PoC
7.8
CVSS 3.1
Description
In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded audio streaming library. The program reads untrusted long ID3 tag value from malicious audio files and uses unbounded appendf() to write formatted strings into ps_ptr heap buffer without length validation. Successful exploitation allows attackers to execute arbitrary code, leak sensitive memory data, cause device crash, or escalate privileges via a crafted malicious audio file.

Metadata

CVE ID
CVE-2026-51273
State
PUBLISHED
Assigner
mitre
Reserved
2026-06-07 00:00 UTC
Published
2026-07-28 00:00 UTC
Last updated
2026-07-28 17:53 UTC
Primary CWE
CWE-122
CWE-122 Heap-based Buffer Overflow
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-122 adp CWE-122 Heap-based Buffer Overflow
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.8 HIGH 3.1 adp CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Back to overview