Metrics
Affected Vendors & Products
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Heatmiser
Heatmiser heatmiser Wifi Thermostat |
|
| Vendors & Products |
Heatmiser
Heatmiser heatmiser Wifi Thermostat |
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields to gain administrative access to the thermostat. | |
| Title | Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm | |
| Weaknesses | CWE-256 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T19:26:56.914Z
Reserved: 2026-05-29T11:39:31.982Z
Link: CVE-2018-25396
Updated: 2026-05-29T19:26:42.591Z
Status : Received
Published: 2026-05-29T16:16:19.107
Modified: 2026-05-29T16:16:19.107
Link: CVE-2018-25396
No data.
OpenCVE Enrichment
Updated: 2026-05-29T17:45:04Z