Junglewise Threat Intelligence

CVE-2024-34268: EQ-3 Eqiva CC-RT-BLE improper authentication in Bluetooth connection

CVE-2024-34268 · Severity: high · CVSS 7.1 · Published 2026-07-16

Executive brief

The EQ-3 Eqiva CC-RT-BLE is a smart radiator thermostat that allows users to control their home heating via Bluetooth. A security flaw in the device's firmware allows anyone within Bluetooth range to connect to and control the thermostat without needing a password or physical pairing process. An attacker could use this to change temperature settings or disable the device, potentially leading to increased energy costs or discomfort for the occupants.

Technical details

The vulnerability is classified as an improper access control issue (CWE-284) within the Bluetooth GATT (Generic Attribute Profile) implementation. The firmware fails to enforce pairing or authentication before allowing access to the device's GATT characteristics. An attacker within Bluetooth range (adjacent) can establish a connection and read or write to these characteristics without any prior credentials or user interaction. This allows for full control over the thermostat's functions. The issue is resolved in firmware version 1.48, which can be applied via the manufacturer's 'calor BT' mobile application.

Affected products

  • EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat <= 1.46

Timeline

  • 2024-02-12: disclosed: Vulnerability discovered and reported to manufacturer
  • 2024-02-28: other: Manufacturer confirmed the vulnerability
  • 2026-05-27: advisory: Public advisory released by BDO Security
  • 2026-07-16: patched: NVD publication date (remediation version 1.48 available)

References