|
|
|
|
|
by haswell
465 days ago
|
|
Are you saying that none of the undocumented commands are capable of putting the device into a remotely exploitable state? The fact that it might be necessary to execute these commands locally is separate from the effects of executing those commands and the potential implications for hardware in the wild. A simple example would be a supply chain attack that leverages these commands to compromise what will soon be consumer hardware. |
|
ESP32 devices not using the Bluetooth adapter firmware are unaffected and already running custom closed source (possibly encrypted) code from the supplier.