ESPHome是ESPHome开源的一个配置、管理智能硬件的系统。用于控制Esp8266/Esp32硬件,实现家庭自动化控制。 ESPHome 2025.8.0版本存在安全漏洞,该漏洞源于web_server身份验证检查不当,可能导致未经授权访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ESPHome 2025.8.0 contains an authentication bypass caused by improper validation of base64-encoded Authorization values in the web_server component, letting attackers access functionality without valid credentials, exploit requires crafted Authorization header. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-57808.yaml | POC Details |
No comments yet