1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Network Thermostat
- Equipment: X-Series WiFi thermostats
- Vulnerability: Missing Authentication for Critical Function
2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to gain full administrative access to the device.
3. TECHNICAL DETAILS
3.1 AFFECTED PRODUCTS
The following Network Thermostat product is affected:
- X-Series WiFi thermostats: Versions v4.5 up to but not including v4.6
- X-Series WiFi thermostats: Versions v9.6 up to but not including v9.46
- X-Series WiFi thermostats: Versions v10.1 up to but not including v10.29
- X-Series WiFi thermostats: Versions v11.1 up to but not including v11.5
3.2 Vulnerability Overview
3.2.1 Missing Authentication for Critical Function CWE-306
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the Local Area Network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat’s embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.
CVE-2025-6260 has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
A CVSS v4 score has also been calculated for CVE-2025-6260. A base score of 9.3 has been calculated; the CVSS vector string is (This article has been indexed from All CISA Advisories