Tasmota is an open-source firmware project for embedded IoT and smart-home devices, with a modestly represented vulnerability footprint centered on its single core firmware product. The observed weakness classes—cross-site scripting in web interfaces and out-of-bounds write conditions in firmware handling—reflect the embedded web-server and memory-constrained attack surface typical of microcontroller-based IoT platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tasmota Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43294CRITICAL Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the ClientPortPtr parameter at lib/libesp32/rtsp/CRtspSession.cpp. | Nov 14, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-36603MEDIUM Cross Site Scripting (XSS) in Tasmota firmware 6.5.0 allows remote attackers to inject JavaScript code via a crafted string in the field "Friendly Name 1". | Jan 9, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tasmota Project.
Media articles that mention a CVE ID that affects a product developed by Tasmota Project — matched by CVE ID, not by vendor name.