EQ-3 Eqiva CC-RT-BLE
- <= 1.46
A vulnerability in the EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat has been identified in all firmware versions up to and including 1.46. This vulnerability allows unsecured Bluetooth connections, enabling attackers to gain full access to the device without authentication. The issue arises because the thermostat's Bluetooth GATT characteristics can be accessed without prior pairing.
Exploitation of this vulnerability allows unauthorized access to the affected thermostat, enabling full control over the device.
Users are advised to update the thermostat firmware to version 1.48, which can be done using the manufacturer's 'calor BT' app.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.