CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:A/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
High
EPSS
Percentile
78.5%
Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.
Vendor | Product | Version | CPE |
---|---|---|---|
radiothermostat | ct50_firmware | * | cpe:2.3:o:radiothermostat:ct50_firmware:*:*:*:*:*:*:*:* |
radiothermostat | ct50 | - | cpe:2.3:h:radiothermostat:ct50:-:*:*:*:*:*:*:* |
radiothermostat | ct80_firmware | * | cpe:2.3:o:radiothermostat:ct80_firmware:*:*:*:*:*:*:*:* |
radiothermostat | ct80 | - | cpe:2.3:h:radiothermostat:ct80:-:*:*:*:*:*:*:* |