EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.
History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Eq-3
Eq-3 eqiva Cc-rt-ble
Vendors & Products Eq-3
Eq-3 eqiva Cc-rt-ble

Fri, 31 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Bluetooth Connection Enables Full Control of EQ-3 Radiator Thermostat

Sat, 25 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unsecured Bluetooth Connection Enables Full Device Control on EQ‑3 Eqiva Thermostat

Wed, 22 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unsecured Bluetooth Connection Enables Full Device Control on EQ‑3 Eqiva Thermostat

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AC:L/AV:A/A:L/C:N/I:H/PR:N/S:U/UI:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-07-16T00:00:00.000Z

Updated: 2026-07-17T13:39:24.468Z

Reserved: 2024-05-02T00:00:00.000Z

Link: CVE-2024-34268

cve-icon Vulnrichment

Updated: 2026-07-17T13:39:16.615Z

cve-icon NVD

No data.

cve-icon Redhat

No data.