CVE-2025-57808: ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

Published Sep 2, 2025
·
Updated

Summary On the ESP-IDF platform, ESPHome's webserver authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value (e.g., correct username with partial password). This allows access to webserver functionality (including OTA, if enabled) without knowing any information about the correct username or password.

Details The HTTP basic auth check in webserveridf's AsyncWebServerRequest::authenticate only compares up to auth.value().size() - authprefixlen bytes of the base64-encoded user:pass string. This means a client-provided valuer like dXNlcjpz (user:s) will pass the check when the correct value is much longer, e.g., dXNlcjpzb21lcmVhbGx5bG9uZ3Bhc3M= (user:somereallylongpass).

Furthermore, the check will also pass when the supplied value is the empty string, which removes the need to know (or brute force) the username. A browser won't generally issue such a request, but it can easily be done by manually constructing the Authorizaztion request header (e.g., via curl).

PoC Configure ESPHome as follows:

yaml esp32: board: ... framework: type: esp-idf webserver: auth: username: user password: somereallylongpass

In a browser, you can correctly log in by supplying username user and password somereallylongpass... but you can also incorrectly log in by supplying substrings of the password whose base64-encoded digest matches a prefix of the correct digest. (For example, I was able to log into an ESPHome device so configured by supplying password some... or even just s.)

You can also use a tool like curl to manually set an Authorization request header that always passes the check without any knowledge of the username:

$ curl -D- http://example.local/ HTTP/1.1 401 Unauthorized ...

$ curl -D- -H 'Authorization: Basic ' http://example.local/ HTTP/1.1 200 OK ...

Impact This vulnerability effectively nullifies basic auth support for the ESP-IDF webserver, allowing auth bypass from another device on the local network with no knowledge of the correct username or password required.

Remediation This vulnerability is fixed in 2025.8.1 and later.

For older versions, disabling the webserver component on ESP-IDF devices may be prudent, particularly if OTA updates through webserver are enabled.

Other sources

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's webserver authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to webserver functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.

MITRE

Affected Software

3 affected componentsFixes available
ESPHome ESP-IDF>=2025.8.0, <2025.8.1
pip/esphome<=2025.8.0
2025.8.1
ESPHome Esphome Firmware=2025.8.0

Event History

Sep 2, 2025
CVE Published
via MITRE·12:26 AM
Data Sourced
via MITRE·12:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·04:46 PM
Data Sourced
via GitHub·04:46 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-57808?

CVE-2025-57808 has been classified as a moderate severity vulnerability.

2

How do I fix CVE-2025-57808?

To fix CVE-2025-57808, users should upgrade to ESPHome version 2025.8.1 or later.

3

What is the impact of CVE-2025-57808?

CVE-2025-57808 may allow unauthorized access due to incorrect handling of web_server authentication.

4

Who is affected by CVE-2025-57808?

CVE-2025-57808 affects users of ESPHome version 2025.8.0 on the ESP-IDF platform.

5

Is there a workaround for CVE-2025-57808?

Currently, there is no documented workaround for CVE-2025-57808 except for updating the software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203