ESPHome
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 28, 2021 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
ESPHome vulnerable to stored Cross-site Scripting in edit configuration file API
ESPHome remote code execution via arbitrary file write
web_server allows OTA update without checking user defined basic auth username & password
Monitor ESPHome in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.