CVE-2018-25396
Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields to gain administrative access to the thermostat.
| CWE | CWE-256 |
| Vendor | heatmiser |
| Product | heatmiser wifi thermostat |
| Published | May 29, 2026 |
| Last Updated | May 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for heatmiser heatmiser wifi thermostat
Be the first to know when new high vulnerabilities affecting heatmiser heatmiser wifi thermostat are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Heatmiser / Heatmiser Wifi Thermostat
1.7
References
Credits
d0wnp0ur