CVE-2025-6260

CRITICAL

Thermostat - Unauthenticated RCE

Title source: llm
STIX 2.1

Description

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-205-02

Scores

CVSS v3 9.8
EPSS 0.0046
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (4)
Network Thermostat/X-Series WiFi thermostats v10.1 - v10.29
Network Thermostat/X-Series WiFi thermostats v11.1 - v11.5
Network Thermostat/X-Series WiFi thermostats v4.5 - 4.6
Network Thermostat/X-Series WiFi thermostats v9.6 - v9.46
Published Jul 24, 2025
Tracked Since Feb 18, 2026