Tarlogic researchers find an undocumented “backdoor” in Chinese manufacturer Espressif's ESP32 microchip used in 1B+ devices for WiFi and Bluetooth connectivity
The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains …
BleepingComputerBill Toulas
Context & Ripple Effects
This report extends a recurring wireless-device security pattern: flaws or undocumented access paths can sit below the operating system, where downstream device makers have limited visibility. Earlier coverage traced a similar issue to a backdoor in Huawei-owned HiSilicon chips used in smart devices.
The scale also echoes Wi-Fi chip flaws that affected billions of devices and the Bluetooth firmware issues covered in the BrakTooth research. The important distinction is that the ESP32 is a widely reused connectivity component, making supplier-level disclosure central to the response.
First-order effects
Espressif and companies shipping ESP32-based products must assess what the reported undocumented functionality does, which products and firmware versions are affected, and whether mitigation or updates are needed.
Device owners and operators gain a new supply-chain risk to track in products whose Wi-Fi and Bluetooth capabilities depend on the component.
Second-order effects
Product makers may face pressure to seek stronger security documentation, testing evidence, and incident-response commitments from connectivity-chip suppliers before selecting parts.
Competing chip vendors can differentiate on firmware transparency and security support, while independent researchers gain another reason to scrutinize embedded radio stacks.
Third-order effects
If repeated findings continue, embedded-device buyers may treat component-level security assurance as a procurement requirement rather than relying on the finished-device brand alone.
The pattern points toward more scrutiny of opaque wireless firmware and chip interfaces; whether it produces common disclosure standards depends on vendor and buyer follow-through.
The trend: This is one data point in the shift from endpoint security toward supplier-level assurance for the radio chips and firmware embedded across connected devices.
Here's to everyone who told me that bluetooth was “fine” and I was overreacting about how insecure it is. Somehow, “I told you so” doesn't quite cover it. — www.bleepingcomputer.com/news/ securit...
So... uh... well... I guess I'm not using many of these in sensitive contexts, but the one that controls my garage door gets unplugged today. — www.bleepingcomputer.com/news/ securit...
Why do we give these Chinese companies the benefit of the doubt every ... single ... time.? This wasn't a mistake. — “Espressif has not publicly documented these commands, so either they weren't meant to be accessible, or they were left in by mistake.” — www.bleepingcomputer…
“The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence. — www.bleepingcomputer.com/news/ securit...
Real bad, there are millions of ESP32 devices out there 😢 — “Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and [...] infect sensitive devices such as mobile phones, computers, smart locks or medical equipment [...]” — www.bleepingco…
#ESP32, which is broadly used in IoT devices like for example in home automation, has some serious security flaws. A Spanish researcher found up to 30 undocumented commands, which can be characterized as backdoor. — by @netalexx.bsky.social — www.bleepingcomputer.com/news/ s…
Oh dammit. The ESP32 platform is great, but at $2/each, I'm not sure what I expected. — Time to review my firewall rules. — www.bleepingcomputer.com/news/ securit...