# CVE-2025-57808

## Summary

- **CVE ID:** CVE-2025-57808
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-303
- **Published:** Sep 2, 2025
- **Last Modified:** Mar 13, 2026

## Description

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.

## Affected Products

- esphome — esphome (= 2025.8.0)

## References

- [CNA](https://github.com/esphome/esphome/security/advisories/GHSA-mxh2-ccgj-8635)
- [CNA](https://github.com/esphome/esphome/commit/2aceb56606ec8afec5f49c92e140c8050a6ccbe5)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.57%
- **EPSS Percentile:** 73.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._