← Back

Radiothermostat

radiothermostat

2 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Ct50 Firmware
ct50_firmware
Ct80 Firmware
ct80_firmware
Ct50
ct50
Ct80
ct80

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Radiothermostat
2Ct50 Firmware
Ct80 Firmware
Nov 21, 2024
May 20, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonstrated by a tstat t_he...Show more
The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonstrated by a tstat t_heat request that accesses a device purchased in the Spring of 2018, and sets a home's target temperature to 95 degrees Fahrenheit. This vulnerability might be described as an addendum to CVE-2013-4860.Show less
1Radiothermostat
4Ct50
Ct50 FirmwareCt80+1 more
May 6, 2026
Jun 5, 2014
N/A· v4
N/A· v3
8.3 HIGH· v2
Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other...Show more
Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.Show less