{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/esphome/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:esphome:device-builder:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["esphome-device-builder (\u003c 1.0.10)"],"_cs_severities":["high"],"_cs_tags":["auth-bypass","remote-code-execution","home-assistant","esphome"],"_cs_type":"advisory","_cs_vendors":["ESPHome"],"content_html":"\u003cp\u003eThe ESPHome device builder dashboard component for Home Assistant contains an authentication bypass vulnerability (CVE-2026-59177) that exposes an unauthenticated ingress site to the local network. The dashboard is designed to rely on the Home Assistant supervisor to provide authentication for ingress traffic. However, the add-on incorrectly bound the ingress site to all interfaces (0.0.0.0) instead of the loopback and supervisor gateway addresses.\u003c/p\u003e\n\u003cp\u003eBecause the add-on operates in host network mode, this configuration exposes the dashboard directly to the host's LAN interface. Any device on the same local network as the Home Assistant host can access the dashboard without authentication. Given that the dashboard's capabilities include running arbitrary Python code and system shell commands, an attacker can leverage this exposure to gain full remote code execution on the Home Assistant host, including control over the configuration directory and managed ESPHome devices. The vulnerability was present by default in all host-network installs prior to version 1.0.10.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network discovery on the local area network to identify the Home Assistant host IP address.\u003c/li\u003e\n\u003cli\u003eAttacker probes the Home Assistant host on the known add-on ingress port to identify the ESPHome dashboard service.\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP GET request to the ingress port, confirming access to the dashboard interface.\u003c/li\u003e\n\u003cli\u003eAttacker navigates the dashboard to the compile/validation section, which supports arbitrary code execution.\u003c/li\u003e\n\u003cli\u003eAttacker uploads a malicious ESPHome configuration file containing an \u003ccode\u003eexternal_components\u003c/code\u003e definition with embedded Python payloads.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the dashboard compile function, causing the backend to execute the injected Python code or shell commands with the privileges of the Home Assistant add-on process.\u003c/li\u003e\n\u003cli\u003eAttacker achieves persistent access or full system control by deploying a reverse shell or modifying the Home Assistant configuration files.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full compromise of the Home Assistant add-on and the underlying host. The attacker gains the ability to read or modify arbitrary files within the mounted configuration and data directories, and can execute system-level commands. This vulnerability affects any Home Assistant instance running the host-networked ESPHome add-on, posing a critical risk to users on shared or untrusted local networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the \u003ccode\u003eesphome\u003c/code\u003e container to include \u003ccode\u003eesphome-device-builder\u003c/code\u003e version 1.0.10 or later.\u003c/li\u003e\n\u003cli\u003eImplement network-layer access control on the Home Assistant host to restrict access to the ESPHome ingress port, ensuring only the local loopback and the supervisor gateway (172.30.32.1) are permitted.\u003c/li\u003e\n\u003cli\u003eAudit the Home Assistant configuration directory for unauthorized modifications or newly created files that may indicate previous exploitation of this interface.\u003c/li\u003e\n\u003cli\u003eSegment the Home Assistant host from untrusted IoT devices or guest network segments to mitigate the risk of unauthorized local network access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T00:51:02Z","date_published":"2026-09-10T00:51:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-esphome-dashboard-auth-bypass/","summary":"An auth bypass in the ESPHome Home Assistant add-on allows unauthenticated LAN access to the dashboard due to improper interface binding, enabling remote code execution on the host.","title":"Unauthenticated Access to ESPHome Dashboard via Ingress Interface Misconfiguration","url":"https://feed.craftedsignal.io/briefs/2026-09-esphome-dashboard-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Esphome","version":"https://jsonfeed.org/version/1.1"}