CVE-2018-25396 - CVE House
Back to Database
Status published High CVE-2018-25396

Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm

Vulnerability Description

Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields to gain administrative access to the thermostat.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25396

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • d0wnp0ur

Affected Vendor

Affected Software

Heatmiser Wifi Thermostat
Vulnerable Versions:
1.7

Timeline

Official Publish: May 29th, 2026
Last Modified: May 29th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)