CVE-2025-6260: Network Thermostat X-Series Wifi Thermostats
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user credentials by manipulating specific elements of the embedded web interface.
Affected products
- Network Thermostat X-Series Wifi Thermostats: from v4.5, before 4.6 (fixed in 4.6); from v9.6, before v9.46 (fixed in v9.46); from v10.1, before v10.29 (fixed in v10.29); from v11.1, before v11.5 (fixed in v11.5)
Published 2025-07-24. Last modified 2026-06-17.