Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Espressif

First CVE: May 13, 2019Active for: 7 yearsTotal CVEs: 45
27.2
VTI Score
Low

Espressif develops widely embedded microcontroller platforms and firmware development frameworks, particularly the ESP32 and ESP8266 series, which power a broad range of IoT devices, smart home products, and connected embedded systems deployed across consumer and industrial contexts. The vendor's vulnerability footprint, though modest in volume, reaches a prominent position in the landscape because of the ubiquity and long-lived nature of its deployed silicon and the supply-chain depth of its SDK and toolchain. A meaningful share of the vendor's disclosures reach serious severity, and the exposure recurs consistently across core products such as the ESP-IDF development framework and the ESP32/ESP8266 SoCs through weakness classes including improper input validation, buffer overflows, and out-of-bounds read and write conditions that are characteristic of constrained embedded firmware. Defenders should inventory Espressif-based devices in their environment and prioritize firmware updates for internet-connected or remotely managed instances; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
45
Total CVEs
More Total CVEs than 98% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Espressif over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 13, 2019
7 years ago
Most Recent CVE
Jun 10, 2026
44 days ago

Products(67 total)

Top CVEs

Signals from CVEs in this vendor scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-45328HIGH
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c a
Jun 10, 20268.836NONO
CVE-2026-42854CRITICAL
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino
May 12, 20269.836NONO
CVE-2026-41429HIGH
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruptio
Apr 24, 20268.834NONO
CVE-2026-45541HIGH
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprot
Jun 10, 20267.531NONO
CVE-2026-45542HIGH
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SR
Jun 10, 20267.129NONO
CVE-2026-42855HIGH
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementa
May 12, 20267.529NONO
CVE-2025-66409CRITICAL
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, when AVRCP is enabled on ESP32, receiving a malformed VE
Dec 2, 20259.128NONO
CVE-2025-55297HIGH
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential hand
Aug 21, 20258.828NONO
CVE-2022-24893HIGH
ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during prov
Jun 25, 20228.828NONO
CVE-2026-45160MEDIUM
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server opt
Jun 10, 20266.527NONO
View all 45 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products45 CVEs
51%
42%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (4.4%)
Network14 (31.1%)
Unknown0 (0.0%)
Physical9 (20.0%)
Adjacent Network20 (44.4%)
Attack Complexity
Low41 (91.1%)
High4 (8.9%)
Unknown0 (0.0%)
User Interaction
None41 (91.1%)
Unknown0 (0.0%)
Required4 (8.9%)
Privileges Required
Low4 (8.9%)
High2 (4.4%)
None39 (86.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Espressif.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Espressif — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Espressif's Products

View all 2 CNAs →

Top CWEs