Open-source firmware report

OpenBeken

Alternative firmware for BK7231, ESP32 and other Wi-Fi smart-home chips.

github.com/openshwprojects/OpenBK7231T_App · 47 components read from oss-openshwprojects__OpenBK7231T_App.cdx.json (analysed 2026-10-11) · checked against today's advisories 2026-10-11

Vulnerabilities affecting this build

28reported by a scanner that checks NVD
49reported by Firmpath
20only in vendors' own advisories, or not yet in NVD for this version

1 more comes from OSV and was not checked against NVD; counted as ours, claimed for neither.

4to upgrade
3to look at
3clear
37no advisory source

To upgrade

A published vulnerability affects the version this build uses.

mbedtls 3.6.4 Upgrade to 3.6.7 or later30 vulnerabilities · an NVD scanner reports 13
nimble 1.6.0 Upgrade to 1.10.0 or later12 vulnerabilities · an NVD scanner reports 12
  • CVE-2026-45815 nimble high
    Remote reachable assertion in ATT Read Multiple Variable Response handler
  • CVE-2025-52435 nimble high
    Invalid error handling in pause encryption procedure in NimBLE controller
  • CVE-2025-62235 nimble high
    Incorrect handling of SMP Security Request could lead to undesirable pairing
  • CVE-2024-51569 nimble high
    Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
  • CVE-2026-45813 nimble high
    Incorrect data validation in BASS add/modify source operation
  • CVE-2026-45811 nimble high
    Buffer overflow in socket HCI transport
  • CVE-2025-53477 nimble high
    NULL Pointer Dereference in NimBLE host HCI layer
  • CVE-2026-45816 nimble high
    NULL pointer dereference vulnerability in SMP LTK request
  • CVE-2026-45812 nimble medium
    OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
  • CVE-2024-47249 nimble medium
    Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
  • CVE-2026-46452 nimble medium
    Mesh Proxy SAR reassembly unbounded append and unchecked failure
  • CVE-2025-53470 nimble low
    Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
esp-idf 5.5.1 Upgrade to 5.5.2 or later6 vulnerabilities · an NVD scanner reports 3
  • CVE-2025-66409 espressif medium
    Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling
  • CVE-2025-65092 espressif missed by NVD scannersmedium
    ESP32-P4 JPEG Decoder Header Parsing Vulnerability
  • CVE-2025-68474 espressif medium
    Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling
  • CVE-2025-64342 espressif missed by NVD scannersmedium
    ESP32 Bluetooth Controller Invalid Access Address Vulnerability
  • CVE-2025-68473 espressif medium
    Out-of-Bounds Write in ESP32 Bluetooth SDP Result Handling
  • CVE-2020-26142 espressif missed by NVD scannersmedium
    Vulnerable Espressif WLAN device processes every single fragmented AMPDU frame as an independent and a full frame
berry 1.1.0.. Listed for this exact version. Open the CVEs to find the fix.1 vulnerability · an NVD scanner reports 0
  • CVE-2026-3285 OSV
    berry-lang berry be_lexer.c scan_string out-of-bounds

To look at

Version numbers cannot settle these: usually a vendor's fork that may already carry the fix.

lwip 2.2.0 A vendor fork: check whether it carries the fixes1 vulnerability · an NVD scanner reports 1
  • CVE-2020-22283 silabs high
    Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information
openthread version not stated A vendor fork with no release version. Check the vendor's notes on these advisories.8 vulnerabilities · an NVD scanner reports 1
  • CVE-2023-41095 silabs high
    Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices
  • CVE-2023-2626 openthread missed by NVD scannershigh
    Missing Key ID Mode validation when processing 6LoWPAN frames
  • CVE-2023-41096 silabs missed by NVD scannershigh
    Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices
  • A-00000463 silabs missed by NVD scannershigh
    OpenThread Vulnerability - Key ID Mode 2 Security
  • CVE-2023-45199 silabs missed by NVD scannersmedium
    Due to a buffer overflow in TLS handshake processing, a malicious peer may be able to gain remote code execution by sending overly long packets
  • CVE-2023-41097 silabs missed by NVD scannersmedium
    Due to a padding oracle, attackers with access to precise time measurement may be able to learn confidential information protected by AES-CBC or RSA OAEP without requiring key information
  • CVE-2025-2329 silabs missed by NVD scannersmedium
    Heavy traffic environment results in denial of service
  • A-00000492 silabs missed by NVD scannersmedium
    A bug in TLS MAC length calculation may cause a buffer overread
coex-lib version not stated Bundled in an SDK with no version of its own. Check the advisories.1 vulnerability · an NVD scanner reports 0
  • CVE-2021-26706 silabs missed by NVD scannersmedium
    Update to “BadAlloc” Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations

No advisory source

No vendor advisory, NVD or OSV record has ever named these. That is not the same as safe: nobody is publishing about them.

How this was made, and what it is not

We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.

It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.