CISA warnt vor kritischem Auth-Bypass in Network Thermostat X-Series
Juli 24, 2025 • César Daniel Barreto

CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America. The flaw, CVE-2025-6260, carries a CVSS v3.1 score of 9.8 and is a case of missing authentication for a critical function.
Full control without a password
The problem lies in the thermostat’s embedded web server, which allows unauthenticated access. By manipulating specific elements of the web interface, an attacker can reset user credentials and gain direct access to the embedded server — effectively taking full administrative control of the device. No credentials and no user interaction are required.
Why the exposure is serious
An attacker on the same local network can reach these devices directly, and any unit sitting behind a router with port forwarding configured can be attacked straight from the internet. Building-automation gear like this is frequently left internet-exposed, which turns a single unpatched thermostat into a foothold on an operational network.
Fixed versions and mitigations
CISA lists several affected firmware ranges — v4.5 up to v4.6, v9.6 up to v9.46, v10.1 up to v10.29, and v11.1 up to v11.5 — with the fix being an update to at least v4.6, v9.46, v10.29, or v11.5 respectively. The vendor reports the update was pushed automatically to reachable online units, but operators should verify the running firmware on every device rather than assume coverage. As always, keep control devices off the public internet, behind firewalls, isolated from business networks, and disable port forwarding to the thermostat.

César Daniel Barreto
César Daniel Barreto ist ein geschätzter Cybersecurity-Autor und -Experte, der für sein fundiertes Wissen und seine Fähigkeit, komplexe Cybersicherheitsthemen zu vereinfachen. Mit seiner umfassenden Erfahrung in den Bereichen Netzwerk Netzwerksicherheit und Datenschutz schreibt er regelmäßig aufschlussreiche Artikel und Analysen über die neuesten Trends in der Cybersicherheit, um sowohl Fachleute als auch die Öffentlichkeit zu informieren.