CVE-2026-46532
- EPSS 0.23%
- Veröffentlicht 10.06.2026 00:35:30
- Zuletzt bearbeitet 11.06.2026 17:36:20
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd() in components/bt/host/bluedroi...
CVE-2026-45542
- EPSS 0.33%
- Veröffentlicht 10.06.2026 00:34:53
- Zuletzt bearbeitet 11.06.2026 17:41:04
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase ha...
CVE-2026-45329
- EPSS 0.12%
- Veröffentlicht 10.06.2026 00:34:09
- Zuletzt bearbeitet 11.06.2026 18:04:26
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only some of the caller-supplied pointer arg...
CVE-2026-45328
- EPSS 0.13%
- Veröffentlicht 10.06.2026 00:33:43
- Zuletzt bearbeitet 11.06.2026 18:15:51
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user applicat...
CVE-2026-45160
- EPSS 0.25%
- Veröffentlicht 10.06.2026 00:26:34
- Zuletzt bearbeitet 11.06.2026 18:22:05
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_options() in components/lwip/apps/dhcpserver/dhcpser...
CVE-2026-45541
- EPSS 0.44%
- Veröffentlicht 10.06.2026 00:25:59
- Zuletzt bearbeitet 11.06.2026 18:05:25
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the esp_http_server component. While parsing ...
CVE-2026-25508
- EPSS 0.2%
- Veröffentlicht 04.02.2026 18:16:09
- Zuletzt bearbeitet 20.02.2026 17:13:08
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, an out-of-bounds read vulnerability was reported in the BLE ATT Prepare Write handling of the BLE provisioning transport (prot...
CVE-2026-25507
- EPSS 0.2%
- Veröffentlicht 04.02.2026 18:16:09
- Zuletzt bearbeitet 20.02.2026 17:12:46
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerability was reported in the BLE provisioning transport (protocomm_ble) layer. The issue can be triggere...
- EPSS 0.21%
- Veröffentlicht 04.02.2026 18:16:09
- Zuletzt bearbeitet 20.02.2026 17:13:48
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implementation where malformed EAP-WSC packets with truncat...
CVE-2025-68474
- EPSS 0.3%
- Veröffentlicht 26.12.2025 23:57:54
- Zuletzt bearbeitet 22.01.2026 16:00:51
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrc_vendor_msg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using...