Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

espressif — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting espressif. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Espressif Systems specializes in low-power Wi-Fi and Bluetooth microcontrollers, primarily serving the Internet of Things market with its ESP8266 and ESP32 series. These embedded devices are frequently targeted due to their widespread deployment in consumer electronics and industrial automation. Historically, security audits have identified critical vulnerabilities including remote code execution, buffer overflows, and improper access controls within the firmware and SDK components. Notable incidents involve flaws allowing unauthorized network access or denial-of-service attacks, often stemming from insufficient input validation in network stack implementations. The company has responded by issuing firmware updates and enhancing secure boot mechanisms, yet the complexity of integrating these chips into diverse third-party applications continues to pose significant security challenges for end-users who may lack the resources to patch legacy devices effectively.

HighCVE-2020-414292026-04-25
Improper validation of NBNS name_len in arduino-esp32 NetBIOS leads to memory corruption · Advisory · espressif/arduino-
High2026-02-05
fix(protocomm): Add security checks for buffer overflow and incorrect… · espressif/esp-idf@4c3fdcd · GitHub
High2026-02-05
fix(protocomm): Add security checks for buffer overflow and incorrect… · espressif/esp-idf@47552ff · GitHub
High2026-02-05
fix(protocomm): Add security checks for buffer overflow and incorrect… · espressif/esp-idf@1ff264a · GitHub
High2026-02-05
fix(protocomm): Add security checks for buffer overflow and incorrect… · espressif/esp-idf@0540c85 · GitHub
High2026-02-05
fix(esp_wifi): Fix invalid memory accesses in supplicant code · espressif/esp-idf@60f992a · GitHub
MediumCVE-2026-255322026-02-05
WPS Enrollee Fragment Integer Underflow Vulnerability · Advisory · espressif/esp-idf · GitHub
UnknownCVE-2026-255082026-02-05
Out-of-Bounds Read Vulnerability in BLE Provisioning · Advisory · espressif/esp-idf · GitHub
MediumCVE-2025-686572026-01-20
Double-Free Race Condition in USB Host HID Device Close Path · Advisory · espressif/esp-usb · GitHub
MediumCVE-2025-664092025-12-04
Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling · Advisory · espressif/esp-idf · GitHub
MediumCVE-2025-650922025-11-22
ESP32-P4 JPEG Decoder Header Parsing Vulnerability · Advisory · espressif/esp-idf · GitHub
Unknown2025-11-22
fix(jpeg): Add check for jpeg marker parser in order to enhance safety · espressif/esp-idf@c79cb4d · GitHub
Medium2025-11-18
ESP32 Bluetooth Controller Invalid Access Address Vulnerability · Advisory · espressif/esp-idf · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with espressif. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.