Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
54 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.2) | 0.34% | — | Espressif Esp-idf | 21/8/2025 | 17/6/2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: Wi-Fi credential handling and Diffie–Hellman key exchange. This vulnerability is fixed in 5.4.1, 5.3.3, 5.1.6, and 5.0.9. | |
| Aplazada | Alta (8.7) | 0.32% | — | Arduino Esp32AIEspressif Esp32AIEspressif Esp32-s2AIEspressif Esp32-s3AI+3 | 7/7/2025 | 17/6/2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Several OTA update examples and the HTTPUpdateServer implementation are vulnerable to Cross-Site Request Forgery (CSRF). The update endpoints accept POST requests for firmware uploads without CSRF… | |
| Analizada | Alta (7.2) | 0.91% | — | Espressif Esp-idf | 24/6/2025 | 17/6/2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been identified in the ESP-NOW protocol implementation within the ESP Wi-Fi component of versions 5.4.1, 5.3.3, 5.2.5, and 5.1.6 of the ESP-IDF framework. This issue stems from insufficient validation of… | |
| Analizada | Alta (8.8) | 0.64% | — | Espressif Esp-idf | 13/3/2025 | 17/6/2026 | Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks. | |
| Analizada | Media (6.8) | 1.4% | — | Espressif Esp32 Firmware | 8/3/2025 | 17/6/2026 | Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory). | |
| Aplazada | Media (6.6) | 0.60% | — | Espressif Esp-idfAI | 12/12/2024 | 17/6/2026 | ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. The IV is set to zero and remains constant throughout the product's… | |
| Analizada | Alta (7.5) | 0.53% | — | Espressif Esp-idf | 7/11/2024 | 17/6/2026 | An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet. | |
| Analizada | Alta (8.1) | 0.97% | — | Espressif Esp-idf | 17/10/2024 | 17/6/2026 | Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component. | |
| Aplazada | Media (6.5) | 0.44% | — | Espressif ESP NOWAI | 12/9/2024 | 17/6/2026 | ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there is no check for the addrs_num field of the group type message. This can result in memory corruption related attacks.… | |
| Analizada | Media (6.5) | 0.30% | — | Espressif Esp-now | 12/9/2024 | 17/6/2026 | ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it is a single, shared resource for all kinds of messages, whether they are broadcast or unicast, and… | |
| Analizada | Media (6.5) | 1.1% | — | Espressif Esp-idf | 14/5/2024 | 17/6/2026 | Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component. | |
| Analizada | Media (5.7) | 0.22% | — | Espressif Esp-idf | 25/3/2024 | 17/6/2026 | ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implementation of the ESP-IDF bootloader which could allow an attacker with physical access to flash of the device to bypass anti-rollback… | |
| Modificada | Alta (7.5) | 0.48% | — | Espressif Esptool | 9/11/2023 | 17/6/2026 | An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm. | |
| Modificada | Media (6.8) | 0.22% | — | Espressif Esp32-d0wd-v3 FirmwareEspressif Esp32-d0wdr2-v3 FirmwareEspressif Esp32-u4wdh FirmwareEspressif Esp32-pico-v3 Firmware+18 | 17/7/2023 | 17/6/2026 | An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the… | |
| Modificada | Alta (8.8) | 0.52% | — | Espressif Esp-idf | 25/6/2022 | 17/6/2026 | ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can result in memory corruption related attacks… | |
| Modificada | Alta (8.8) | 1.4% | — | Espressif Esp-idf | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page upon reception of an LMP Feature Response Extended packet, allowing attackers in radio range to trigger arbitrary code execution in ESP32 via a crafted Extended Features bitfield payload. | |
| Modificada | Media (6.5) | 0.84% | — | Espressif Esp-idf | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP… | |
| Modificada | Media (6.5) | 0.82% | — | Espressif Esp-idf | 7/9/2021 | 17/6/2026 | The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data. | |
| Modificada | Alta (7.5) | 1.5% | — | Espressif Esp32 Firmware | 14/7/2021 | 17/6/2026 | An attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa frame. The device requires a reboot to recover. | |
| Modificada | Alta (7.5) | 1.4% | — | Espressif Esp-idf | 12/1/2021 | 17/6/2026 | Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic… | |
| Modificada | Media (6.5) | 0.87% | — | Espressif Esp-idf | 31/8/2020 | 17/6/2026 | The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the… | |
| Modificada | Media (6.5) | 0.81% | — | Espressif Esp-idf | 31/8/2020 | 17/6/2026 | The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet. | |
| Modificada | Media (6.8) | 0.45% | — | Espressif Esp-idfEspressif Esp8266 Nonos SDKEspressif Esp8266 Rtos SDK | 23/7/2020 | 17/6/2026 | An encryption-bypass issue was discovered on Espressif ESP-IDF devices through 4.2, ESP8266_NONOS_SDK devices through 3.0.3, and ESP8266_RTOS_SDK devices through 3.3. Broadcasting forged beacon frames forces a device to change its authentication mode to OPEN, effectively disabling its 802.11 encryption. | |
| Modificada | Media (4.6) | 0.24% | — | Espressif Esp32-d0wd FirmwareEspressif Esp32-d2wd FirmwareEspressif Esp32-s0wd FirmwareEspressif Esp32-pico-d4 Firmware | 14/11/2019 | 17/6/2026 | An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by… | |
| Modificada | Media (6.8) | 0.44% | — | Espressif Esp-idf | 7/10/2019 | 17/6/2026 | An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3.x through 3.3.1. An attacker who uses fault injection to physically disrupt the ESP32 CPU can bypass the Secure Boot digest verification at startup, and boot unverified code from flash. The fault… |