The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Jul 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface. | |
Title | Network Thermostat X-Series WiFi Thermostats Missing Authentication for Critical Function | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-07-24T20:53:17.534Z
Updated: 2025-07-25T13:31:50.926Z
Reserved: 2025-06-18T22:35:45.412Z
Link: CVE-2025-6260

Updated: 2025-07-25T13:31:46.205Z

Status : Awaiting Analysis
Published: 2025-07-24T21:15:52.447
Modified: 2025-07-25T15:29:19.837
Link: CVE-2025-6260

No data.