Vulnerability threat dossier

CVE-2025-57808

esphomeesphome firmware

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.

VTP deterministic threat0.3of 100 · CVSS excluded

VTP analyst assessment

ESPHome web authentication bypass

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factUNKNOWN

Assessment

ESPHome 2025.8.0 on ESP-IDF can incorrectly accept an empty or substring Authorization value, allowing adjacent-network access to web_server functionality and potentially OTA when enabled. CVSS is 8.1 and EPSS is 0.01571; no exploitation evidence is supplied.

Why it matters

  • Authentication can be bypassed without knowing the configured credential.
  • OTA exposure could permit consequential firmware changes if that function is enabled.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Affected device presence, web_server reachability, and OTA enablement are unknown.

The supplied description is truncated, and public exploitation and first-party observation are unknown.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

ESPHome 2025.8.0 devices using ESP-IDF.

AI baseline history (1)
  1. BASELINE ASSESSED
    ESPHome web authentication bypassgpt-5.6-sol · high
Technical severityHIGHCVSS 8.1 · technical context
Public exploitationUNKNOWNGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.0274th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
HIGH

Honeypot request semantics are strongly consistent with CVE-2025-57808. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 100/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.02; this is predictive context, not exploitation evidence.

  2. 02

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

    05

    Original publications

    Source record

    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score0.3vtp-threat-v1-public
    Public exploitation0 / 30
    EPSS prediction0.31 / 20
    Exploit availability0 / 15
    Source independence0 / 15
    Intelligence recency0 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    8.1 · HIGH
    Vector
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    CWE
    CWE-303
    CPE records
    1
    Deterministic history records
    20
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.