CVE-2025-6260 Details
Description
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.
A vulnerability has been identified in the embedded web server of Network Thermostat X-Series WiFi thermostats, specifically in versions 4.5 prior to 4.6, 9.6 prior to 9.46, 10.1 prior to 10.29, and 11.1 prior to 11.5. This vulnerability allows unauthenticated attackers to gain direct access to the thermostat's web server. Exploitation can occur from the local area network or over the Internet if port forwarding is enabled on the router. Once accessed, attackers can manipulate elements of the web interface to reset user credentials.
Users are advised to update their X-Series WiFi thermostats to version 4.6 or later, version 9.46 or later, version 10.29 or later, or version 11.5 or later. This update was automatically applied to reachable units. For units behind firewalls, contact Network Thermostat to coordinate an update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2025CISA-ADP
Assessed Jul 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-205-02 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Network Thermostat X-Series WiFi Thermostats | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2025 | New CVE Received | [email protected] |
Volerion