CVE-2025-57808 describes an authentication bypass vulnerability in ESPHome's web_server component, specifically affecting version 2025.8.0 when using the ESP-IDF platform. This flaw allows unauthorized access to web_server functionalities, including Over-The-Air (OTA) updates if enabled, by exploiting an incorrect authentication check where an empty or partial base64-encoded Authorization header is accepted. The vulnerability carries a CVSS score of 8.1 (HIGH), indicating a severe risk due to its low attack complexity, network-adjacent attack vector, and high potential for confidentiality and integrity impact without requiring user interaction or privileges. While there is no evidence of active exploitation (KEV: No) or Metasploit modules, Nuclei templates for this high-severity vulnerability are available, suggesting potential for exploit development. Community discussion and media coverage are currently minimal, which is typical for a newly disclosed CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2025.8.0CPE matchmatch criteria | cpe:2.3:o:esphome:esphome_firmware:2025.8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.