VendorsEspressifesp-idfall versions
Vulnerabilities

Espressif Esp-idf

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

31CVEs
CVE-2025-52471
ESP-NOW Integer Underflow Vulnerability Advisory
Published 2025-06-24 · Analyzed
9.8EPSS 0.009
CVE-2026-45328
ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers
Published 2026-06-10 · Analyzed
9.3EPSS 0.001
CVE-2025-66409
ESF-IDF has an Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling
Published 2025-12-02 · Analyzed
9.1EPSS 0.006
CVE-2021-28139
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigger arbitrary code execution in ESP32 via a crafted Extended Features bitfield payload.
Published 2021-09-07 · Modified
8.8EPSS 0.014
CVE-2024-53406
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.
Published 2025-03-13 · Analyzed
8.8EPSS 0.006
CVE-2022-24893
Espressif Bluetooth Mesh Stack Vulnerable to Out-of-bounds Write leading to memory buffer corruption
Published 2022-06-25 · Modified
8.8EPSS 0.005
CVE-2025-55297
ESF-IDF BluFi Example Memory Overflow Vulnerability
Published 2025-08-21 · Analyzed
8.8EPSS 0.003
CVE-2025-68473
ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling
Published 2025-12-26 · Analyzed
8.6EPSS 0.004
CVE-2024-33453
Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component.
Published 2024-10-17 · Analyzed
8.1EPSS 0.010
CVE-2019-12587
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows the installation of a zero Pairwise Master Key (PMK) after the completion of any EAP authentication method, which allows attackers in radio range to replay, decrypt, or spoof frames via a rogue access point.
Published 2019-09-04 · Modified
8.1EPSS 0.009
CVE-2026-25532
ESF-IDF is Vulnerable to WPS Enrollee Fragment Integer Underflow
Published 2026-02-04 · Analyzed
8.0EPSS 0.002
CVE-2025-68474
ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling
Published 2025-12-26 · Analyzed
7.6EPSS 0.003
CVE-2020-16146
Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.
Published 2021-01-12 · Modified
7.5EPSS 0.014
CVE-2024-51428
An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.
Published 2024-11-07 · Analyzed
7.5EPSS 0.005
CVE-2026-45541
ESF-IDF: Remote Null Pointer Dereference in WebSocket Server
Published 2026-06-10 · Analyzed
7.5EPSS 0.004
CVE-2019-15894
An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3.x through 3.3.1. An attacker who uses fault injection to physically disrupt the ESP32 CPU can bypass the Secure Boot digest verification at startup, and boot unverified code from flash. The fault injection attack does not disable the Flash Encryption feature, so if the ESP32 is configured with the recommended combination of Secure Boot and Flash Encryption, then the impact is minimized. If the ESP32 is configured without Flash Encryption then successful fault injection allows arbitrary code execution. To protect devices with Flash Encryption and Secure Boot enabled against this attack, a firmware change must be made to permanently enable Flash Encryption in the field if it is not already permanently enabled.
Published 2019-10-07 · Modified
7.2EPSS 0.004
CVE-2026-45542
ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth
Published 2026-06-10 · Analyzed
7.1EPSS 0.003
CVE-2026-45329
ESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service Wrappers
Published 2026-06-10 · Analyzed
7.1EPSS 0.001
CVE-2018-18558
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage bootloader allows a physically proximate attacker to bypass secure boot checks and execute arbitrary code, by crafting an application binary that overwrites a bootloader code segment in process_segment in components/bootloader_support/src/esp_image_format.c. The attack is effective when the flash encryption feature is not enabled, or if the attacker finds a different vulnerability that allows them to write this binary to flash memory.
Published 2019-05-13 · Modified
6.9EPSS 0.004
CVE-2020-12638
An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively disabling its 802.11 encryption.
Published 2020-07-23 · Modified
6.8EPSS 0.005
CVE-2019-12586
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
Published 2019-09-04 · Modified
6.5EPSS 0.015
CVE-2024-33454
Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.
Published 2024-05-09 · Analyzed
6.5EPSS 0.011
CVE-2021-28136
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.
Published 2021-09-07 · Modified
6.5EPSS 0.009
CVE-2020-13595
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.
Published 2020-08-31 · Modified
6.5EPSS 0.009
CVE-2021-28135
The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.
Published 2021-09-07 · Modified
6.5EPSS 0.009
CVE-2020-13594
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
Published 2020-08-31 · Modified
6.5EPSS 0.008
CVE-2026-45160
ESF-IDF: Out-of-bounds Read in lwIP DHCP Server Option Parser
Published 2026-06-10 · Analyzed
6.5EPSS 0.002
CVE-2026-25508
ESF-IDF Has Memory Safety Vulnerabilities in BLE Provisioning
Published 2026-02-04 · Analyzed
6.3EPSS 0.002
CVE-2026-25507
ESF-IDF Has Use-after-free Vulnerability in BLE Provisioning
Published 2026-02-04 · Analyzed
6.3EPSS 0.002
CVE-2024-28183
Anti Rollback bypass with physical access and TOCTOU attack
Published 2024-03-25 · Analyzed
6.1EPSS 0.002
CVE-2026-46532
ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser
Published 2026-06-10 · Analyzed
4.6EPSS 0.002