Radiothermostat manufactures a focused line of smart thermostat products, including the CT50 and CT80 models and their associated firmware, that interface directly with home heating and cooling infrastructure. The durable signal across this vendor's vulnerability disclosures centers on improper input validation in these networked control devices, reflecting the challenges of securing embedded web interfaces that handle user commands and remote access. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Radiothermostat over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11315MEDIUM The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature | May 20, 2018 | 6.5 | 21 | NO | NO |
CVE-2013-4860HIGH Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection set | Jun 5, 2014 | 8.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Radiothermostat.
Media articles that mention a CVE ID that affects a product developed by Radiothermostat — matched by CVE ID, not by vendor name.