CISA Warns of Critical Auth Bypass in Network Thermostat X-Series
July 24, 2025 • César Daniel Barreto

CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America. The flaw, CVE-2025-6260, carries a CVSS v3.1 score of 9.8 and is a case of missing authentication for a critical function.
Full control without a password
The problem lies in the thermostat’s embedded web server, which allows unauthenticated access. By manipulating specific elements of the web interface, an attacker can reset user credentials and gain direct access to the embedded server — effectively taking full administrative control of the device. No credentials and no user interaction are required.
Why the exposure is serious
An attacker on the same local network can reach these devices directly, and any unit sitting behind a router with port forwarding configured can be attacked straight from the internet. Building-automation gear like this is frequently left internet-exposed, which turns a single unpatched thermostat into a foothold on an operational network.
Fixed versions and mitigations
CISA lists several affected firmware ranges — v4.5 up to v4.6, v9.6 up to v9.46, v10.1 up to v10.29, and v11.1 up to v11.5 — with the fix being an update to at least v4.6, v9.46, v10.29, or v11.5 respectively. The vendor reports the update was pushed automatically to reachable online units, but operators should verify the running firmware on every device rather than assume coverage. As always, keep control devices off the public internet, behind firewalls, isolated from business networks, and disable port forwarding to the thermostat.

César Daniel Barreto
César Daniel Barreto is an esteemed cybersecurity writer and expert, known for his in-depth knowledge and ability to simplify complex cyber security topics. With extensive experience in network security and data protection, he regularly contributes insightful articles and analysis on the latest cybersecurity trends, educating both professionals and the public.