Логотип exploitDog
bind:CVE-2025-57808
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-57808

Количество 2

Количество 2

nvd логотип

CVE-2025-57808

5 месяцев назад

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-mxh2-ccgj-8635

5 месяцев назад

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-57808

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.

CVSS3: 8.1
4%
Низкий
5 месяцев назад
github логотип
GHSA-mxh2-ccgj-8635

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

CVSS3: 8.1
4%
Низкий
5 месяцев назад

Уязвимостей на страницу