Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26385 | ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header |
Github GHSA |
GHSA-mxh2-ccgj-8635 | ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header |
Wed, 10 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esphome esphome Firmware
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:esphome:esphome_firmware:2025.8.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Esphome esphome Firmware
|
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esphome
Esphome esphome |
|
| Vendors & Products |
Esphome
Esphome esphome |
Tue, 02 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1. | |
| Title | ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header | |
| Weaknesses | CWE-303 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-02T14:03:58.777Z
Reserved: 2025-08-20T14:30:35.010Z
Link: CVE-2025-57808
Updated: 2025-09-02T14:03:51.885Z
Status : Analyzed
Published: 2025-09-02T01:15:29.947
Modified: 2025-09-10T19:03:00.280
Link: CVE-2025-57808
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:05Z
EUVD
Github GHSA