PT-2025-27254 · Unknown · Espasyncwebserver

·

CVE-2025-53094

·

Published

2025-06-27

·

Updated

2025-06-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: ESPAsyncWebServer versions up to and including 3.7.8
Description: A CRLF injection vulnerability exists in the construction and output of HTTP headers within AsyncWebHeader.cpp. Unsanitized input allows attackers to inject CR (r) or LF ( ) characters into header names or values, leading to arbitrary header or response manipulation. This can enable a wide range of attacks.
Recommendations: For versions up to and including 3.7.8, apply the fix available at pull request 211, which is expected to be part of version 3.7.9. As a temporary workaround, consider restricting the input to AsyncWebHeader.cpp to prevent CR and LF character injections until the patch is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15912
CVE-2025-53094
GHSA-87J8-6F7G-H8WH

Affected Products

Espasyncwebserver