CISA Cảnh Báo Về Lỗ Hổng Bỏ Qua Xác Thực Nghiêm Trọng Trong Network Thermostat X-Series
Tháng 7 24, 2025 • César Daniel Barreto

CISA published advisory ICSA-25-205-02 on July 24, 2025, warning of a critical authentication-bypass vulnerability in Network Thermostat’s X-Series WiFi thermostats — devices used widely in commercial facilities across North America. The flaw, CVE-2025-6260, carries a CVSS v3.1 score of 9.8 and is a case of missing authentication for a critical function.
Full control without a password
The problem lies in the thermostat’s embedded web server, which allows unauthenticated access. By manipulating specific elements of the web interface, an attacker can reset user credentials and gain direct access to the embedded server — effectively taking full administrative control of the device. No credentials and no user interaction are required.
Why the exposure is serious
An attacker on the same local network can reach these devices directly, and any unit sitting behind a router with port forwarding configured can be attacked straight from the internet. Building-automation gear like this is frequently left internet-exposed, which turns a single unpatched thermostat into a foothold on an operational network.
Fixed versions and mitigations
CISA lists several affected firmware ranges — v4.5 up to v4.6, v9.6 up to v9.46, v10.1 up to v10.29, and v11.1 up to v11.5 — with the fix being an update to at least v4.6, v9.46, v10.29, or v11.5 respectively. The vendor reports the update was pushed automatically to reachable online units, but operators should verify the running firmware on every device rather than assume coverage. As always, keep control devices off the public internet, behind firewalls, isolated from business networks, and disable port forwarding to the thermostat.

César Daniel Barreto
César Daniel Barreto là một nhà văn và chuyên gia an ninh mạng được kính trọng, nổi tiếng với kiến thức sâu rộng và khả năng đơn giản hóa các chủ đề an ninh mạng phức tạp. Với kinh nghiệm sâu rộng về bảo mật mạng và bảo vệ dữ liệu, ông thường xuyên đóng góp các bài viết và phân tích sâu sắc về các xu hướng an ninh mạng mới nhất, giáo dục cả chuyên gia và công chúng.