Impact
This vulnerability is a classic buffer overflow in the MP3Decoder::UnpackSFMPEG1 function of the schreibfaul1 ESP32-audioI2S library. The overflow arises because attacker‑controlled MP3 metadata is not validated, allowing an adversary to craft a malicious file that corrupts memory and can lead to arbitrary code execution and full compromise of the device.
Affected Systems
The affected product is schreibfaul1 ESP32-audioI2S version 3.4.5. No vendor information is provided in the CNA data, so any deployment of this exact library version is at risk.
Risk and Exploitability
The CVSS score of 9.8 categorizes this flaw as Critical, and although the EPSS score is less than 1 % and the issue is not listed in CISA’s KEV catalog, the potential for remote code execution remains high. The likely attack vector is the delivery of a malicious MP3 file to the device’s decoder, which could be performed over any interface where MP3 data is accepted.
OpenCVE Enrichment