CVE-2025-57808
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/09/2025
Last modified:
10/09/2025
Description
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:esphome:esphome_firmware:2025.8.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



