Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to modify the admin username and password without user consent.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Heatmiser wifi Thermostat
|
|
| CPEs | cpe:2.3:a:heatmiser:wifi_thermostat:1.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Heatmiser wifi Thermostat
|
Mon, 13 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Heatmiser
Heatmiser heatmiser Wifi Thermostat |
|
| Vendors & Products |
Heatmiser
Heatmiser heatmiser Wifi Thermostat |
Sun, 12 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to modify the admin username and password without user consent. | |
| Title | Heatmiser Wifi Thermostat 1.7 Cross-Site Request Forgery | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-12T12:28:53.542Z
Updated: 2026-04-13T18:06:18.134Z
Reserved: 2026-04-12T12:14:01.046Z
Link: CVE-2019-25708
Updated: 2026-04-13T17:58:07.165Z
Status : Analyzed
Published: 2026-04-12T13:16:33.793
Modified: 2026-04-17T19:17:54.973
Link: CVE-2019-25708
No data.