CVE-2019-25322 - CVE House
Back to Database
Status published Critical CVE-2019-25322

Heatmiser Netmonitor 3.03 - Hardcoded Credentials

Vulnerability Description

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25322

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Ismail Tasdelen

Affected Vendor

Affected Software

Heatmiser Netmonitor
Vulnerable Versions:
3.03

Timeline

Official Publish: February 12th, 2026
Last Modified: February 13th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)