VYPR
Medium severity4.3NVD Advisory· Published Apr 12, 2026· Updated Apr 17, 2026

CVE-2019-25708

CVE-2019-25708

Description

Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to modify the admin username and password without user consent.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:heatmiser:wifi_thermostat:1.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:heatmiser:wifi_thermostat:1.7:*:*:*:*:*:*:*
    • (no CPE)range: =1.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.