Heatmiser Netmonitor Hardcoded Credentials Vulnerability

Vulnerability

A hardcoded credentials vulnerability has been identified in Heatmiser Netmonitor version 3.03. The issue resides on the networkSetup.htm page, where hidden form input fields contain predictable admin login credentials. This vulnerability allows unauthorized access to the device using the hard-coded username 'admin' and password 'admin'.

Impact

Exploitation of this vulnerability allows for unauthorized access to the Heatmiser Netmonitor device, enabling an attacker to manipulate thermostat settings and control connected heating systems.

Reproduction

To reproduce this vulnerability, access the networkSetup.htm page on a Heatmiser Netmonitor device running version 3.03. The hidden form 'hidFrm' will contain the hardcoded username 'admin' and password 'admin' in the input fields 'lognm' and 'logpd', respectively. This information can be used to log into the device with administrative privileges.

Added: Feb 12, 2026, 11:46 PM
Updated: Feb 12, 2026, 11:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
3.0
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.