# Espressif says ESP32 undocumented Bluetooth HCI commands are not a backdoor

DevFeed: [Espressif says ESP32 undocumented Bluetooth HCI commands are not a backdoor](<https://devfeed.tech/articles/esp32-undocumented-bluetooth-commands-clearing-the-air-13684.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2025/03/esp32-bluetooth-clearing-the-air/>)

Author: John Lee

Published: 2025-03-10T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Bluetooth](<https://devfeed.tech/topics/bluetooth.md>), [Security](<https://devfeed.tech/topics/security.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [bluetooth](<https://devfeed.tech/tags/bluetooth.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [hci](<https://devfeed.tech/tags/hci.md>), [iot](<https://devfeed.tech/tags/iot.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

Espressif explains that the reported undocumented ESP32 Bluetooth HCI commands are controller debug commands. It says they do not participate in normal HCI communication with NimBLE or Bluedroid and do not pose a security threat or backdoor.

## Source excerpt

Overview# Espressif has already provided a formal response to the recently published claims about ESP32 Bluetooth controller serving as a potential "backdoor" or having "undocumented features" that can cause security concerns. This post highlights the technical details about the relevant commands (HCI Commands) that were undocumented and establishes that the mentioned undocumented HCI commands do not pose a security threat and are certainly not a "backdoor".