CVE-2025-57808
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.
Published:Sep 2, 2025
Last Modified:Sep 10, 2025
EPS:Sep 2, 2025
EPSS Score:0.00026
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Esphome
Product
Esphome
Esphome
Esphome
Vendor
Esphome
Product
Esphome Firmware
Esphome
Esphome Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
