ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-26385 ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
Github GHSA Github GHSA GHSA-mxh2-ccgj-8635 ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 10 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Esphome esphome Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:esphome:esphome_firmware:2025.8.0:*:*:*:*:*:*:*
Vendors & Products Esphome esphome Firmware

Tue, 02 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Esphome
Esphome esphome
Vendors & Products Esphome
Esphome esphome

Tue, 02 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 02 Sep 2025 00:45:00 +0000

Type Values Removed Values Added
Description ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.
Title ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
Weaknesses CWE-303
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-02T14:03:58.777Z

Reserved: 2025-08-20T14:30:35.010Z

Link: CVE-2025-57808

cve-icon Vulnrichment

Updated: 2025-09-02T14:03:51.885Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-02T01:15:29.947

Modified: 2025-09-10T19:03:00.280

Link: CVE-2025-57808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-02T15:23:05Z