CVE-2025-57808: ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
Summary On the ESP-IDF platform, ESPHome's webserver authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value (e.g., correct username with partial password). This allows access to webserver functionality (including OTA, if enabled) without knowing any information about the correct username or password.
Details The HTTP basic auth check in webserveridf's AsyncWebServerRequest::authenticate only compares up to auth.value().size() - authprefixlen bytes of the base64-encoded user:pass string. This means a client-provided valuer like dXNlcjpz (user:s) will pass the check when the correct value is much longer, e.g., dXNlcjpzb21lcmVhbGx5bG9uZ3Bhc3M= (user:somereallylongpass).
Furthermore, the check will also pass when the supplied value is the empty string, which removes the need to know (or brute force) the username. A browser won't generally issue such a request, but it can easily be done by manually constructing the Authorizaztion request header (e.g., via curl).
PoC Configure ESPHome as follows:
yaml esp32: board: ... framework: type: esp-idf webserver: auth: username: user password: somereallylongpass
In a browser, you can correctly log in by supplying username user and password somereallylongpass... but you can also incorrectly log in by supplying substrings of the password whose base64-encoded digest matches a prefix of the correct digest. (For example, I was able to log into an ESPHome device so configured by supplying password some... or even just s.)
You can also use a tool like curl to manually set an Authorization request header that always passes the check without any knowledge of the username:
$ curl -D- http://example.local/ HTTP/1.1 401 Unauthorized ...
$ curl -D- -H 'Authorization: Basic ' http://example.local/ HTTP/1.1 200 OK ...
Impact This vulnerability effectively nullifies basic auth support for the ESP-IDF webserver, allowing auth bypass from another device on the local network with no knowledge of the correct username or password required.
Remediation This vulnerability is fixed in 2025.8.1 and later.
For older versions, disabling the webserver component on ESP-IDF devices may be prudent, particularly if OTA updates through webserver are enabled.
Other sources
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's webserver authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to webserver functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57808?
CVE-2025-57808 has been classified as a moderate severity vulnerability.
How do I fix CVE-2025-57808?
To fix CVE-2025-57808, users should upgrade to ESPHome version 2025.8.1 or later.
What is the impact of CVE-2025-57808?
CVE-2025-57808 may allow unauthorized access due to incorrect handling of web_server authentication.
Who is affected by CVE-2025-57808?
CVE-2025-57808 affects users of ESPHome version 2025.8.0 on the ESP-IDF platform.
Is there a workaround for CVE-2025-57808?
Currently, there is no documented workaround for CVE-2025-57808 except for updating the software.