Esp32
Vendor:
First CVE: Aug 31, 2020 · Active for 5 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Esp32 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2020
5 years ago
Most Recent CVE
Apr 24, 2026
92 days ago
CVE Severity & Scoring
Esp328 CVEs
50%
50%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (25.0%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network5 (62.5%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (12.5%)
None7 (87.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41429HIGH arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruptio | Apr 24, 2026 | 8.8 | 30 | NO | NO |
CVE-2021-28139HIGH The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, all | Sep 7, 2021 | 8.8 | 27 | NO | NO |
CVE-2025-27840MEDIUM Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory). | Mar 8, 2025 | 6.8 | 26 | NO | NO |
CVE-2021-41104HIGH ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web | Sep 28, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-34173HIGH An attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa frame. The device requires a reboot to recover | Jul 14, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-28136MEDIUM The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing pr | Sep 7, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-13594MEDIUM The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection | Aug 31, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-13595MEDIUM The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a r | Aug 31, 2020 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Esp32
Top CWEs
Versions
No cataloged versions.