S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 18, 2025

CVE-2025-57808 Scanner

CVE-2025-57808 Scanner - Authentication Bypass vulnerability in ESPHome

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-57808
8.1
CVSShigh
Exploitable from an adjacent network · no authentication required.

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.

Attack Vector
Adjacent
Privileges Req.
None
User Interaction
None
Affected
esphomeby esphome
= 2025.8.0
Updated Aug 19, 2026View on NVD →
Detail

ESPHome is a system designed for building custom firmware for smart home devices. It is commonly used by hobbyists and engineers to configure and manage IoT devices, enhancing automation in residential environments. The platform offers an intuitive dashboard for managing firmware updates and device configurations. Integration with smart home ecosystems like Home Assistant allows for broader compatibility. It is intended to be user-friendly, allowing even those with limited technical skills to manage device firmware. This flexibility makes it a popular choice for DIY smart home solutions.

The vulnerability in ESPHome lies in an authentication bypass within the web_server component. This issue is rooted in improper validation of base64-encoded Authorization headers. Attackers exploiting this vulnerability can access functions without proper credentials. This flaw undermines the security model, potentially allowing unauthorized access to web server operations. Such bypass vulnerabilities are critical, as they can increase the device exposure to unauthorized control. Addressing this vulnerability is crucial to maintaining device security.

The authentication bypass vulnerability involves improper checking of Authorization values. Specifically, base64-encoded values in HTTP headers can be manipulated by attackers. This manipulation allows access to the web server without verifying the authenticity of the request. The vulnerable endpoint is located at the web server's entry point. Attackers use crafted Authorization headers to exploit this flaw. As a result, security-critical operations may be performed without valid user credentials.

If exploited, this vulnerability could lead to significant control compromise in affected devices. Attackers could access OTA update functions, effectively allowing for unauthorized firmware modification. This could include installing malicious firmware, resulting in additional vulnerabilities. The security breach could extend to accessing sensitive device configurations. Furthermore, compromised devices might be leveraged in larger network attacks, impacting broader smart home security. Consequently, unmitigated exploits could severely weaken the overall system integrity.

REFERENCES

Solution Advice
  • Upgrade to ESPHome version 2025.8.1 or later to address the authentication bypass issue.
  • Implement enhanced access control measures to mitigate unauthorized access risks.
  • Regularly audit the Authorization headers to ensure they conform to expected formats.
  • Consider adding anomaly detection for unusual web server access patterns.
  • Regularly update all components to the latest security patches and firmware versions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.