Vulnerabilities > Radiothermostat

DATE CVE VULNERABILITY TITLE RISK
2018-05-20 CVE-2018-11315 Improper Input Validation vulnerability in Radiothermostat Ct50 Firmware and Ct80 Firmware
The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack.
low complexity
radiothermostat CWE-20
6.5
2014-06-05 CVE-2013-4860 Permissions, Privileges, and Access Controls vulnerability in Radiothermostat products
Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.
low complexity
radiothermostat CWE-264
8.3