- EPSS 0.03%
- Veröffentlicht 04.02.2026 18:16:09
- Zuletzt bearbeitet 20.02.2026 17:13:48
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implementation where malformed EAP-WSC packets with truncat...
CVE-2026-25508
- EPSS 0.02%
- Veröffentlicht 04.02.2026 18:16:09
- Zuletzt bearbeitet 20.02.2026 17:13:08
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, an out-of-bounds read vulnerability was reported in the BLE ATT Prepare Write handling of the BLE provisioning transport (prot...
CVE-2026-25507
- EPSS 0.02%
- Veröffentlicht 04.02.2026 18:16:09
- Zuletzt bearbeitet 20.02.2026 17:12:46
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerability was reported in the BLE provisioning transport (protocomm_ble) layer. The issue can be triggere...
CVE-2025-68474
- EPSS 0.01%
- Veröffentlicht 26.12.2025 23:57:54
- Zuletzt bearbeitet 22.01.2026 16:00:51
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrc_vendor_msg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using...
CVE-2025-68473
- EPSS 0.04%
- Veröffentlicht 26.12.2025 23:54:47
- Zuletzt bearbeitet 22.01.2026 16:01:58
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the ESP-IDF Bluetooth host stack (BlueDroid), the function bta_dm_sdp_result() used a fixed-size array uuid_list[3...
CVE-2025-66409
- EPSS 0.08%
- Veröffentlicht 02.12.2025 18:09:03
- Zuletzt bearbeitet 13.02.2026 16:12:30
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VENDOR DEPENDENT command from a peer device can cause the Bluetooth stac...
CVE-2025-65092
- EPSS 0.08%
- Veröffentlicht 21.11.2025 21:33:03
- Zuletzt bearbeitet 25.11.2025 22:16:42
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses its hardware JPEG decoder, the software parser lacks necessary validation checks. A specially crafted (malicious) JPE...
CVE-2025-64342
- EPSS 0.08%
- Veröffentlicht 17.11.2025 17:21:01
- Zuletzt bearbeitet 18.11.2025 14:06:29
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it receives a connection request containing an invalid Access Address (AA) of 0x00000000 or 0xFFFFFFFF, advertising may stop unexpected...
CVE-2025-55297
- EPSS 0.04%
- Veröffentlicht 21.08.2025 15:15:33
- Zuletzt bearbeitet 22.01.2026 16:04:06
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5...
CVE-2025-52471
- EPSS 0.53%
- Veröffentlicht 24.06.2025 19:53:06
- Zuletzt bearbeitet 22.01.2026 16:05:44
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been identified in the ESP-NOW protocol implementation within the ESP Wi-Fi component of versions 5.4.1, 5.3.3, 5.2.5, and 5.1.6 of the ES...