Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-57808

40
FAUCET Score

CVE-2025-57808 describes an authentication bypass vulnerability in ESPHome's web_server component, specifically affecting version 2025.8.0 when using the ESP-IDF platform. This flaw allows unauthorized access to web_server functionalities, including Over-The-Air (OTA) updates if enabled, by exploiting an incorrect authentication check where an empty or partial base64-encoded Authorization header is accepted. The vulnerability carries a CVSS score of 8.1 (HIGH), indicating a severe risk due to its low attack complexity, network-adjacent attack vector, and high potential for confidentiality and integrity impact without requiring user interaction or privileges. While there is no evidence of active exploitation (KEV: No) or Metasploit modules, Nuclei templates for this high-severity vulnerability are available, suggesting potential for exploit development. Community discussion and media coverage are currently minimal, which is typical for a newly disclosed CVE.

Impacted Technologies

VendorProductVersion(s)CPE
2025.8.0CPE matchmatch criteria
cpe:2.3:o:esphome:esphome_firmware:2025.8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.51%
Probability of exploitation in next 30 days
EPSS Percentile
71.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-57808 · Oct 15, 2025
This CVE's current EPSS score of 0.0151 is in the 84th percentile among its peer group of 1,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: esphomeFixed in: 2025.8.1

Vendor Advisories (1)

pipGHSA-mxh2-ccgj-8635high

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

Sep 2, 2025

References

github.com / esphome/esphome/commit/2aceb56606ec8afec5f49c92e140c8050a6ccbe5
Patch
github.com / esphome/esphome/security/advisories/GHSA-mxh2-ccgj-8635
ExploitVendor Advisory