You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Basic auth bypass in esphome
High severity
GitHub Reviewed
Published
Sep 28, 2021
in
esphome/esphome
•
Updated Sep 20, 2024
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Learn more on MITRE.
Impact
Anyone with web_server enabled and HTTP basic auth configured on 2021.9.1 or older
web_serverallows OTA update without checking user defined basic auth username & passwordPatches
Patch released in 2021.9.2
Workarounds
Disable/remove
web_serverReferences