Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to modify the admin username and password without user consent.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/46100 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/heatmiser-wifi-thermostat-cross-site-request-forgery | Third Party Advisory |
Configurations
History
17 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Heatmiser wifi Thermostat
Heatmiser |
|
| CPE | cpe:2.3:a:heatmiser:wifi_thermostat:1.7:*:*:*:*:*:*:* | |
| References | () https://www.exploit-db.com/exploits/46100 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/heatmiser-wifi-thermostat-cross-site-request-forgery - Third Party Advisory |
12 Apr 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-12 13:16
Updated : 2026-04-17 19:17
NVD link : CVE-2019-25708
Mitre link : CVE-2019-25708
CVE.ORG link : CVE-2019-25708
JSON object : View
Products Affected
heatmiser
- wifi_thermostat
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
