Junglewise Threat Intelligence

CVE-2018-25396: Heatmiser Wifi Thermostat credential disclosure in networkSetup.htm

CVE-2018-25396 · Severity: high · CVSS 7.5 · Published 2026-05-29

Executive brief

Heatmiser Wifi Thermostats are smart home devices used to manage heating systems remotely. A security flaw allows anyone with network access to the device to view the administrator's username and password in plain text without logging in. An attacker could use these credentials to take full control of the thermostat, potentially disrupting heating services or using the device as a foothold in the local network.

Technical details

A credential disclosure vulnerability exists in Heatmiser Wifi Thermostat version 1.7 and potentially earlier. The issue stems from the 'networkSetup.htm' endpoint failing to implement proper authentication or authorization checks. An unauthenticated attacker can perform a simple GET request to this page, which contains the administrative username and password stored in plaintext within HTML form fields. This allows for full administrative takeover of the device's web interface. Public exploit scripts are available that automate the extraction of these credentials via common tools like wget and grep.

Affected products

  • Heatmiser Wifi Thermostat 1.7 and earlier

Timeline

  • 2018-08-17: disclosed: Initial discovery by Andrew Tierney
  • 2018-10-16: other: Public exploit script released on Exploit-DB
  • 2026-05-29: advisory: CVE formally published and assigned by VulnCheck

References

Related threats