PT-2026-53104 · Unknown · Xiaozhi-Esp32

·

CVE-2026-13491

·

Published

2026-06-28

·

Updated

2026-06-29

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions xiaozhi-esp32 versions prior to 2.2.7
Description A remote denial of service can be triggered through the manipulation of the session id argument. This issue resides within the Application::GetInstance() function located in the main/protocols/mqtt protocol.cc file of the MQTT Goodbye Handler component. The attack complexity is high and exploitability is considered difficult.
Recommendations Apply patch e182471f8c5a22434346bd98da34d3b66c8c8b3e to resolve the issue.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13491

Affected Products

Xiaozhi-Esp32