Heatmiser Wifi Thermostat Credential Disclosure Vulnerability

Vulnerability

A credential disclosure vulnerability has been identified in the Heatmiser Wifi Thermostat version 1.7. This vulnerability allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. The vulnerability arises because the page exposes plaintext usernames and passwords in HTML form fields, which can be extracted to gain administrative access to the thermostat.

Impact

Exploitation of this vulnerability allows for unauthorized access to the thermostat's administrative interface, potentially leading to unauthorized changes in thermostat settings or functionality.

Reproduction

To reproduce this vulnerability, send a request to the networkSetup.htm endpoint of the Heatmiser Wifi Thermostat. The response will contain plaintext administrative credentials, including the username and password, which can be extracted from the HTML form fields. This can be automated with a simple script that downloads the networkSetup.htm page and parses out the credential information.

Added: May 29, 2026, 4:44 PM
Updated: May 29, 2026, 4:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.2
remediation
0.0
relevance
9.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.