CVE-2025-6260

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.
Configurations

No configuration.

History

24 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 21:15

Updated : 2025-07-25 15:29


NVD link : CVE-2025-6260

Mitre link : CVE-2025-6260

CVE.ORG link : CVE-2025-6260


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function