Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields to gain administrative access to the thermostat.
History

Fri, 29 May 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Heatmiser
Heatmiser heatmiser Wifi Thermostat
Vendors & Products Heatmiser
Heatmiser heatmiser Wifi Thermostat

Fri, 29 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields to gain administrative access to the thermostat.
Title Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-29T14:46:38.389Z

Updated: 2026-05-29T19:26:56.914Z

Reserved: 2026-05-29T11:39:31.982Z

Link: CVE-2018-25396

cve-icon Vulnrichment

Updated: 2026-05-29T19:26:42.591Z

cve-icon NVD

Status : Received

Published: 2026-05-29T16:16:19.107

Modified: 2026-05-29T16:16:19.107

Link: CVE-2018-25396

cve-icon Redhat

No data.