Skip to content
Noroxi

esphome records

6 published records for vendor esphome.

All records

6 records
  • ESPHome remote code execution via arbitrary file write

    HighCVSS 8.8No exploitEPSS 2%

    esphome · esphomeFeb 26, 2024

  • ESPHome vulnerable to stored Cross-site Scripting in edit configuration file API

    HighCVSS 8.7No exploitEPSS 1%

    esphome · esphomeMar 6, 2024

  • ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

    HighCVSS 8.1Proof of conceptEPSS 2%

    esphome · esphome firmwareSep 1, 2025

  • ESPHome vulnerable to Authentication bypass via Cross site request forgery

    HighCVSS 8.1No exploitEPSS 0%

    esphome · esphomeApr 10, 2024

  • web_server allows OTA update without checking user defined basic auth username & password

    HighCVSS 7.5No exploitEPSS 1%

    esphome · esphome firmwareSep 28, 2021

  • ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

    LowCVSS 1.7No exploitEPSS 0%

    esphome · esphomeJan 19, 2026