VendorsESPHomeesphome_firmwareall versions
Vulnerabilities

ESPHome ESPHome Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-57808
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
Published 2025-09-02 · Analyzed
8.1EPSS 0.016
CVE-2021-41104
web_server allows OTA update without checking user defined basic auth username & password
Published 2021-09-28 · Modified
7.5EPSS 0.012