CISA waarschuwt voor kritieke authenticatie-omzeiling in Network Thermostat X-Series

juli 24, 2025 • César Daniel Barreto

Network Thermostat X-Series WiFi Thermostats cybersecurity vulnerability alert CVSS 9.3

CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America. The flaw, CVE-2025-6260, carries a CVSS v3.1 score of 9.8 and is a case of missing authentication for a critical function.

Full control without a password

The problem lies in the thermostat’s embedded web server, which allows unauthenticated access. By manipulating specific elements of the web interface, an attacker can reset user credentials and gain direct access to the embedded server — effectively taking full administrative control of the device. No credentials and no user interaction are required.

Why the exposure is serious

An attacker on the same local network can reach these devices directly, and any unit sitting behind a router with port forwarding configured can be attacked straight from the internet. Building-automation gear like this is frequently left internet-exposed, which turns a single unpatched thermostat into a foothold on an operational network.

Fixed versions and mitigations

CISA lists several affected firmware ranges — v4.5 up to v4.6, v9.6 up to v9.46, v10.1 up to v10.29, and v11.1 up to v11.5 — with the fix being an update to at least v4.6, v9.46, v10.29, or v11.5 respectively. The vendor reports the update was pushed automatically to reachable online units, but operators should verify the running firmware on every device rather than assume coverage. As always, keep control devices off the public internet, behind firewalls, isolated from business networks, and disable port forwarding to the thermostat.

César Daniel Barreto, auteur op het gebied van cybersecurity bij Security Briefing

César Daniel Barreto

César Daniel Barreto is een gewaardeerd schrijver en expert op het gebied van cyberbeveiliging, die bekend staat om zijn diepgaande kennis en zijn vermogen om complexe onderwerpen op het gebied van cyberbeveiliging te vereenvoudigen. Met zijn uitgebreide ervaring in netwerk beveiliging en gegevensbescherming draagt hij regelmatig bij aan inzichtelijke artikelen en analyses over de nieuwste cyberbeveiligingstrends, waarmee hij zowel professionals als het publiek voorlicht.

nl_NLDutch