8.3
CVSSv2

CVE-2013-4860

Published: 05/06/2014 Updated: 29/08/2017
CVSS v2 Base Score: 8.3 | Impact Score: 10 | Exploitability Score: 6.5
VMScore: 739
Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Radio Thermostat CT80 And CT50 with firmware 1.4.64 and previous versions does not restrict access to the API, which allows remote malicious users to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

radiothermostat ct50_firmware

radiothermostat ct50 -

radiothermostat ct80_firmware

radiothermostat ct80 -

Exploits

Radio Thermostat of America, Inc products CT80 and CT50 versions 1464 and prior fail to authenticate any access to their API ...