PT-2026-32170 · Heatmiser · Heatmiser Wifi Thermostat+1

Sajjadbnd

·

Published

2026-04-12

·

Updated

2026-04-12

·

CVE-2019-25708

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to modify the admin username and password without user consent.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-25708

Affected Products

Heatmiser Wifi Thermostat
Wifi Thermostat