ESPHome 2025.8.0 contains an authentication bypass caused by improper validation of base64-encoded Authorization values in the web_server component, letting attackers access functionality without valid credentials, exploit requires crafted Authorization header.
id: CVE-2025-57808
info:
name: ESPHome - Authentication Bypass
author: sean-kim
severity: hig
...