Vulnerabilidades en esphome
8 resultadosAnálisis Vexday
ESPHome apresenta perfil de risco baixo com 6 vulnerabilidades catalogadas, nenhuma sob ataque ativo (KEV) e sem críticas confirmadas. A fraqueza dominante é integer overflow (CWE-190), que tipicamente afeta cálculos e alocação de memória. Não há vulnerabilidades recentes publicadas, indicando estabilidade relativa na base de código.
CVE-2025-57808HIGHESP-IDF web_server basic auth bypass using empty or incomplete Authorization headerEPSS 1.6%CVE-2024-27081HIGHESPHome remote code execution via arbitrary file writeEPSS 1.5%CVE-2021-41104HIGHweb_server allows OTA update without checking user defined basic auth username & passwordEPSS 1.2%CVE-2024-27287MEDIUMESPHome vulnerable to stored Cross-site Scripting in edit configuration file APIEPSS 0.7%CVE-2026-23833LOWESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API componentEPSS 0.3%CVE-2024-29019HIGHESPHome vulnerable to Authentication bypass via Cross site request forgeryEPSS 0.3%CVE-2026-71260MEDIUMESPHome web_server Plaintext Password Disclosure via JSON "value" FieldEPSS 0.2%CVE-2026-71259HIGHESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code ExecutionEPSS 0.1%