Heatmiser Wifi Thermostat
- <= 1.7
A credential disclosure vulnerability has been identified in the Heatmiser Wifi Thermostat version 1.7. This vulnerability allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. The vulnerability arises because the page exposes plaintext usernames and passwords in HTML form fields, which can be extracted to gain administrative access to the thermostat.
Exploitation of this vulnerability allows for unauthorized access to the thermostat's administrative interface, potentially leading to unauthorized changes in thermostat settings or functionality.
To reproduce this vulnerability, send a request to the networkSetup.htm endpoint of the Heatmiser Wifi Thermostat. The response will contain plaintext administrative credentials, including the username and password, which can be extracted from the HTML form fields. This can be automated with a simple script that downloads the networkSetup.htm page and parses out the credential information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.