CISA advarer om kritisk autorisationsomgåelse i Network Thermostat X-Series
juli 24, 2025 • César Daniel Barreto

CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America. The flaw, CVE-2025-6260, carries a CVSS v3.1 score of 9.8 and is a case of missing authentication for a critical function.
Full control without a password
The problem lies in the thermostat’s embedded web server, which allows unauthenticated access. By manipulating specific elements of the web interface, an attacker can reset user credentials and gain direct access to the embedded server — effectively taking full administrative control of the device. No credentials and no user interaction are required.
Why the exposure is serious
An attacker on the same local network can reach these devices directly, and any unit sitting behind a router with port forwarding configured can be attacked straight from the internet. Building-automation gear like this is frequently left internet-exposed, which turns a single unpatched thermostat into a foothold on an operational network.
Fixed versions and mitigations
CISA lists several affected firmware ranges — v4.5 up to v4.6, v9.6 up to v9.46, v10.1 up to v10.29, and v11.1 up to v11.5 — with the fix being an update to at least v4.6, v9.46, v10.29, or v11.5 respectively. The vendor reports the update was pushed automatically to reachable online units, but operators should verify the running firmware on every device rather than assume coverage. As always, keep control devices off the public internet, behind firewalls, isolated from business networks, and disable port forwarding to the thermostat.

César Daniel Barreto
César Daniel Barreto er en anerkendt cybersikkerhedsskribent og -ekspert, der er kendt for sin dybdegående viden og evne til at forenkle komplekse cybersikkerhedsemner. Med omfattende erfaring inden for netværks sikkerhed og databeskyttelse bidrager han regelmæssigt med indsigtsfulde artikler og analyser om de seneste cybersikkerhedstendenser og uddanner både fagfolk og offentligheden.