Authentication Flaw in ESPHome Web Server by Espressif Systems
CVE-2025-57808
What is CVE-2025-57808?
CVE-2025-57808 is a vulnerability discovered in the ESPHome web server, a platform developed by Espressif Systems that allows for the remote control and management of microcontrollers within home automation systems. This particular vulnerability arises from an authentication flaw in versions prior to 2025.8.1 of the ESP-IDF platform, where the web server's authentication checks can be bypassed under specific conditions.
When a malformed or empty base64-encoded Authorization value is provided by a client, the system may incorrectly grant access, enabling attackers to exploit the web server functionality without possessing legitimate credentials. This includes access to features like over-the-air (OTA) updates, which poses a significant risk, as it could allow unauthorized individuals to modify or control devices connected to the home automation network, potentially leading to unauthorized surveillance or manipulation of home environments.
Potential impact of CVE-2025-57808
-
Unauthorized Access: Victims of this vulnerability may face unauthorized access to their home automation systems, as attackers can bypass the authentication process, compromising the integrity of security measures put in place to protect the user’s devices and data.
-
Compromise of System Functionality: Once attackers gain access, they can utilize features such as OTA updates to alter device firmware or configurations, which can lead to the malfunction of devices, loss of data, or repurposing of devices for malicious activities.
-
Increased Vulnerability to Future Attacks: The existence of this flaw not only exposes individuals to immediate risks but may also pave the way for additional attacks, as compromised devices could serve as entry points for further exploitation within a network, potentially leading to larger-scale security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
esphome = 2025.8.0
