Heatmiser Wifi Thermostat Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the Heatmiser Wifi Thermostat version 1.7. This vulnerability allows attackers to change administrator credentials by deceiving authenticated users into submitting malicious requests. Exploitation involves crafting HTML forms that target the 'networkSetup.htm' endpoint, using specific parameters to alter the admin username and password without the user's consent.

Impact

Exploitation of this vulnerability allows for unauthorized modification of admin credentials on the affected thermostat.

Reproduction

To reproduce this vulnerability, an attacker must create an HTML form that includes the 'usnm', 'usps', and 'cfps' parameters. This form should be directed to the 'networkSetup.htm' endpoint. When an authenticated user is tricked into submitting this form, the admin username and password will be changed without their knowledge.

Added: Apr 12, 2026, 1:19 PM
Updated: Apr 12, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.3
remediation
0.0
relevance
5.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.