PT-2025-27254 · Unknown · Espasyncwebserver

Jlleitschuh

·

Published

2025-06-27

·

Updated

2025-06-28

·

CVE-2025-53094

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: ESPAsyncWebServer versions up to and including 3.7.8
Description: A CRLF injection vulnerability exists in the construction and output of HTTP headers within AsyncWebHeader.cpp. Unsanitized input allows attackers to inject CR (r) or LF ( ) characters into header names or values, leading to arbitrary header or response manipulation. This can enable a wide range of attacks.
Recommendations: For versions up to and including 3.7.8, apply the fix available at pull request 211, which is expected to be part of version 3.7.9. As a temporary workaround, consider restricting the input to AsyncWebHeader.cpp to prevent CR and LF character injections until the patch is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-15912
CVE-2025-53094
GHSA-87J8-6F7G-H8WH

Affected Products

Espasyncwebserver