CVE-2025-6260

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) El servidor web integrado en los rangos de versiones del termostato enumerados contiene una vulnerabilidad que permite a atacantes no autenticados, ya sea en la red de área local o desde Internet a través de un enrutador con reenvío de puertos configurado, obtener acceso directo al servidor web integrado del termostato y restablecer las credenciales del usuario manipulando elementos específicos de la interfaz web integrada.

24 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 21:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-6260

Mitre link : CVE-2025-6260

CVE.ORG link : CVE-2025-6260


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function