ESPHome is an open-source firmware and configuration framework for embedded IoT devices and microcontrollers, with a modestly distributed user base spanning home automation, industrial IoT, and DIY electronics applications. Observed vulnerabilities in the framework and firmware concentrate around input handling and authentication, including path traversal, cross-site scripting, and authentication algorithm implementation issues that recur across the product's web-facing and configuration interfaces. Current severity, exploitation, and remediation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Esphome over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57808HIGH ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can | Sep 2, 2025 | 8.1 | 40 | NO | YES |
CVE-2026-23833HIGH ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2025.12.6, an integer overflow in the API component's protobu | Jan 19, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-27081HIGH ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command l | Feb 26, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-41104HIGH ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web | Sep 28, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-27287HIGH ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file API in da | Mar 6, 2024 | 8.7 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Esphome.
Media articles that mention a CVE ID that affects a product developed by Esphome — matched by CVE ID, not by vendor name.