OpenBeken
Alternative firmware for BK7231, ESP32 and other Wi-Fi smart-home chips.
Vulnerabilities affecting this build
To upgrade
mbedtls 3.6.4 Upgrade to 3.6.7 or later30 vulnerabilities · an NVD scanner reports 13
- CVE-2025-59438 silabs critical
Padding oracle through timing of cipher error reporting
- CVE-2026-50580 mbedtls missed by NVD scannershigh
Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake
- CVE-2026-49300 mbedtls missed by NVD scannershigh
X.509 CA bit forgery via invalid basicConstraints extension
- CVE-2026-50579 mbedtls missed by NVD scannershigh
Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context
- CVE-2026-25835 mbedtls high
PSA random generator cloning
- CVE-2026-50713 mbedtls missed by NVD scannershigh
Heap corruption with early renegotiation after corrupted record in DTLS
- CVE-2026-50584 mbedtls missed by NVD scannersmedium
ChaCha20 counter overflow can reuse keystream
- CVE-2026-50587 mbedtls missed by NVD scannersmedium
Timing side-channel in RSA PKCS#1 v1.5 decryption
- CVE-2026-35336 mbedtls missed by NVD scannersmedium
Possible buffer overflow in mbedtls_ecdh_calc_secret()
- CVE-2026-50640 mbedtls missed by NVD scannerslow
Ignored TLS 1.3 resumption secret derivation error
- CVE-2026-25833 mbedtls low
Buffer underflow in x509_inet_pton_ipv6()
- CVE-2026-50583 mbedtls missed by NVD scannerslow
Out-of-bounds read when parsing a zero-length ECC public key
- CVE-2026-25834 mbedtls low
Signature Algorithm Injection
- CVE-2026-50581 mbedtls missed by NVD scannerslow
Extended master secret calculation failure ignored
- CVE-2026-50586 mbedtls missed by NVD scannerslow
Information disclosure in TLS 1.2 NewSessionTicket
- CVE-2025-54764 silabs critical
Side channel in RSA key generation and operations
- CVE-2026-34873 mbedtls high
Client impersonation while resuming a TLS 1.3 session
- CVE-2026-34875 mbedtls high
Buffer overflow in FFDH public key export
- CVE-2026-34876 mbedtls high
CCM multipart finish tag-length validation bypass
- CVE-2026-34874 mbedtls high
Null pointer dereference when setting a distinguished name
- CVE-2026-34872 mbedtls medium
FFDH: lack of contributory behaviour due to improper input validation
- CVE-2026-73096 mbedtls missed by NVD scannersmedium
TLS 1.3 early data integrity failure due to buffered plaintext across key change
- CVE-2026-54435 mbedtls missed by NVD scannersmedium
Side channel leak in ECC optimized modp
- CVE-2026-50585 mbedtls missed by NVD scannersmedium
Incomplete context reset in mbedtls_ssl_session_reset()
- CVE-2026-54441 mbedtls missed by NVD scannerslow
Signature algorithm restrictions not enforced on certificate chain
- CVE-2026-73064 mbedtls missed by NVD scannerslow
A random generator fault can compromise TLS data integrity
- CVE-2025-66442 mbedtls low
Compiler-induced constant-time violations
- CVE-2026-34871 mbedtls low
Entropy on Linux can fall back to /dev/urandom
- CVE-2026-34877 mbedtls low
Risk of insufficient protection of serialized session or context data leading to potential memory safety issues
- CVE-2026-50588 mbedtls missed by NVD scannerslow
Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing
nimble 1.6.0 Upgrade to 1.10.0 or later12 vulnerabilities · an NVD scanner reports 12
- CVE-2026-45815 nimble high
Remote reachable assertion in ATT Read Multiple Variable Response handler
- CVE-2025-52435 nimble high
Invalid error handling in pause encryption procedure in NimBLE controller
- CVE-2025-62235 nimble high
Incorrect handling of SMP Security Request could lead to undesirable pairing
- CVE-2024-51569 nimble high
Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
- CVE-2026-45813 nimble high
Incorrect data validation in BASS add/modify source operation
- CVE-2026-45811 nimble high
Buffer overflow in socket HCI transport
- CVE-2025-53477 nimble high
NULL Pointer Dereference in NimBLE host HCI layer
- CVE-2026-45816 nimble high
NULL pointer dereference vulnerability in SMP LTK request
- CVE-2026-45812 nimble medium
OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
- CVE-2024-47249 nimble medium
Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
- CVE-2026-46452 nimble medium
Mesh Proxy SAR reassembly unbounded append and unchecked failure
- CVE-2025-53470 nimble low
Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
esp-idf 5.5.1 Upgrade to 5.5.2 or later6 vulnerabilities · an NVD scanner reports 3
- CVE-2025-66409 espressif medium
Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling
- CVE-2025-65092 espressif missed by NVD scannersmedium
ESP32-P4 JPEG Decoder Header Parsing Vulnerability
- CVE-2025-68474 espressif medium
Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling
- CVE-2025-64342 espressif missed by NVD scannersmedium
ESP32 Bluetooth Controller Invalid Access Address Vulnerability
- CVE-2025-68473 espressif medium
Out-of-Bounds Write in ESP32 Bluetooth SDP Result Handling
- CVE-2020-26142 espressif missed by NVD scannersmedium
Vulnerable Espressif WLAN device processes every single fragmented AMPDU frame as an independent and a full frame
berry 1.1.0.. Listed for this exact version. Open the CVEs to find the fix.1 vulnerability · an NVD scanner reports 0
- CVE-2026-3285 OSV
berry-lang berry be_lexer.c scan_string out-of-bounds
To look at
lwip 2.2.0 A vendor fork: check whether it carries the fixes1 vulnerability · an NVD scanner reports 1
- CVE-2020-22283 silabs high
Buffer overflow vulnerability via a crafted ICMPv6 message may lead to accessing sensitive information
openthread version not stated A vendor fork with no release version. Check the vendor's notes on these advisories.8 vulnerabilities · an NVD scanner reports 1
- CVE-2023-41095 silabs high
Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices
- CVE-2023-2626 openthread missed by NVD scannershigh
Missing Key ID Mode validation when processing 6LoWPAN frames
- CVE-2023-41096 silabs missed by NVD scannershigh
Keys Stored in Plaintext on Secure Vault High for Silabs Ember ZNet and OpenThread devices
- A-00000463 silabs missed by NVD scannershigh
OpenThread Vulnerability - Key ID Mode 2 Security
- CVE-2023-45199 silabs missed by NVD scannersmedium
Due to a buffer overflow in TLS handshake processing, a malicious peer may be able to gain remote code execution by sending overly long packets
- CVE-2023-41097 silabs missed by NVD scannersmedium
Due to a padding oracle, attackers with access to precise time measurement may be able to learn confidential information protected by AES-CBC or RSA OAEP without requiring key information
- CVE-2025-2329 silabs missed by NVD scannersmedium
Heavy traffic environment results in denial of service
- A-00000492 silabs missed by NVD scannersmedium
A bug in TLS MAC length calculation may cause a buffer overread
coex-lib version not stated Bundled in an SDK with no version of its own. Check the advisories.1 vulnerability · an NVD scanner reports 0
- CVE-2021-26706 silabs missed by NVD scannersmedium
Update to “BadAlloc” Security Vulnerability in Micrium OS Dynamic Memory Pool Allocations
No advisory source
- beken-freertos-sdk f5a64d4cda03bac6d885f4f30c27bbd3435c5e3a
- bouffalo-sdk 2.3.26..2.3.27
- cmock v2.5.2-2-geeecc49ce8af
- esp-ble-mesh-lib
- esp-phy-lib
- esp-thread-lib
- esp32-bt-lib
- esp32-wifi-lib
- esp32c2-bt-lib
- esp32c3-bt-lib
- esp32c5-bt-lib
- esp32c6-bt-lib
- esp32h2-bt-lib
- mqtt
- openbk7231n 07fd9e0e2da0aabaddab00be2a897589be235158
- openbk7231t d9411f8808990d8e1dc3767f3aa548a7444e1c01
- openbk7239n 3f1b4f4ce1798a7d062467160f64dea37020f9ee
- openbl602 e0efddc364037ed2b2cd79dae3e51f3e21a75177
- openecr6600 1aa42baa4cbb0781c716f75da28b6371da81215c
- openesp8266 67a4c26e81ab8b7703c3cf9e4a9178c6245ba277
- opengd32vw553 8b859b21d57bc6b508dc13675c222c893aaec767
- openln8825 2.0..
- openln882h 84149f251efc120561bdefa17ce399f62eadb8be
- openrda5981 46cd5bf6b352615ce4ba0c44ce8634855a233ebc
- openrtl8710a-b 5d8d26b2cb68f4041a48cca6beae6eb69f34456a
- openrtl8720d ad3d02c713286a1da04e7025d0aa74f5214080dc
- openrtl87x0c 1e7a2048dc97d1bd37bd62fffc2d49c422ca214a
- opentr6260 a6f72569d0fa195396440bb018d87a43595f334b
- opentxw81x 05bd1742cd07e6d91f1276ca87baae374e156798
- openw600 db909ce9100e389f45c9ccfd155f755b8dd3a350
- openw800 f917fe93389846f7762e1f40b2cf9593749ad760
- openxr806 3113bbb32f8378206f52d72406aa123a1368bfec
- openxr809 b35b75ce118dc25ecdf0d767f79a5f5dac5144cf
- openxr872 84deedb8e2014e6b5252f2b21055fa31eb3d4b90
- spiffs 0.2-255-g0dbb3f71c5f6
- tlsf
- unity v2.6.0-RC1
How this was made, and what it is not
We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.
It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.