🔐 CVE Alert

CVE-2026-25599

MEDIUM 6.3

Missing authentication and clear‑text data transmission affecting Orca heat pumps

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
5th

Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca server over an unencrypted and unauthenticated HTTP connection on a non-secure port specifically enable an attacker to impersonate a legitimate device and inject malicious payloads. This enables the insertion of harmful code directly into the Orca user portal, potentially compromising user accounts, exposing sensitive information, and allowing further unauthorized actions within the portal.

CWE CWE-79 CWE-306 CWE-319
Vendor orca energy
Product orca heat pump
Published Jun 1, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for orca energy orca heat pump

Be the first to know when new medium vulnerabilities affecting orca energy orca heat pump are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

Orca Energy / Orca heat pump
0 < 2.1.0
Orca Energy / Orca user portal
0 < 1.19

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.si: https://www.cert.si/en/cve-2026-25599/

Credits

Tom Kern, NIL d.o.o.