PT-2026-40455 · Espressif Systems · Arduino-Esp32
Published
2026-05-12
·
Updated
2026-05-13
·
CVE-2026-42855
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
arduino-esp32 versions prior to 3.3.8
Description
The WebServer Digest authentication implementation computes the authentication hash using the URI field from the client's Authorization header without verifying that it matches the actual requested URI. This allows an attacker with a valid digest response for one URI to authenticate requests to a different protected URI, bypassing per-resource access control.
Recommendations
Update to version 3.3.8.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arduino-Esp32