Key Information 1. Vulnerability Overview Vulnerability Type: Missing Authentication for Critical Function (CVE-306) CVSS v4.9.3: High Affected Scope: Multiple versions of Network Thermostat X-Series WiFi Thermostats 2. Affected Products X-Series WiFi thermostats: Versions from v8.5u to v9.6 (excluding v9.6) X-Series WiFi thermostats: Versions from v8.6u to v9.45 (excluding v9.45) X-Series WiFi thermostats: Versions from v9.5u to v10.20 (excluding v10.20) X-Series WiFi thermostats: Versions from v10.1u to v11.5 (excluding v11.5) 3. Vulnerability Details Description: The embedded web server allows unauthorized access over local or internet networks by forging specific HTTP requests and responses. CVSS Score: 9.5 (Critical) 4. Affected Sectors Critical Infrastructure Sector: Commercial Facilities Affected Regions: United States, Canada Company Headquarters Location: United States 5. Mitigation Measures Update to the latest firmware versions: - X-Series WiFi thermostats: At least v9.6 - X-Series WiFi thermostats: At least v9.45 - X-Series WiFi thermostats: At least v10.20 - X-Series WiFi thermostats: At least v11.5 Basic defensive measures: - Limit network exposure - Isolate control system networks using firewalls - Use more secure methods such as VPN for remote access 6. Reporter Yousuf Kandil reported this vulnerability to CISA.