Junglewise Threat Intelligence

CVE-2019-25708: Heatmiser Wifi Thermostat CSRF in networkSetup.htm

CVE-2019-25708 · Severity: medium · CVSS 4.3 · Published 2026-04-12

Executive brief

A vulnerability in Heatmiser Wifi Thermostats allows an attacker to change the device's administrator username and password. By tricking a logged-in user into visiting a malicious website, the attacker can take full control of the thermostat's settings. This could lead to unauthorized access to home climate controls and potential disruption of service.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Heatmiser Wifi Thermostat version 1.7. The issue resides in the 'networkSetup.htm' endpoint, which fails to implement sufficient CSRF protections such as anti-forgery tokens. An attacker can craft a malicious HTML form using the 'usnm', 'usps', and 'cfps' parameters to modify the administrative username and password. Exploitation requires an authenticated administrator to be tricked into interacting with a malicious link or page while their session is active. Successful exploitation results in a complete takeover of the device's administrative interface.

Affected products

  • Heatmiser Wifi Thermostat 1.7

Timeline

  • 2019-01-09: disclosed: Initial exploit published on Exploit-DB
  • 2026-04-12: advisory: NVD and VulnCheck advisory published

References

Related threats