Executive brief
A vulnerability in Heatmiser Wifi Thermostats allows an attacker to change the device's administrator username and password. By tricking a logged-in user into visiting a malicious website, the attacker can take full control of the thermostat's settings. This could lead to unauthorized access to home climate controls and potential disruption of service.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Heatmiser Wifi Thermostat version 1.7. The issue resides in the 'networkSetup.htm' endpoint, which fails to implement sufficient CSRF protections such as anti-forgery tokens. An attacker can craft a malicious HTML form using the 'usnm', 'usps', and 'cfps' parameters to modify the administrative username and password. Exploitation requires an authenticated administrator to be tricked into interacting with a malicious link or page while their session is active. Successful exploitation results in a complete takeover of the device's administrative interface.
Affected products
- Heatmiser Wifi Thermostat 1.7
Timeline
- 2019-01-09: disclosed: Initial exploit published on Exploit-DB
- 2026-04-12: advisory: NVD and VulnCheck advisory published