Home

Description

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.

PUBLISHED Reserved 2026-02-12 | Published 2026-02-12 | Updated 2026-02-13 | Assigner VulnCheck




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

Use of Hard-coded Credentials

Product status

3.03
affected

Credits

Ismail Tasdelen finder

References

www.exploit-db.com/exploits/47823 (ExploitDB-47823) exploit

web.archive.org/...90724160628/https://www.heatmiser.com/en/ (Archived Heatmiser Official Website) product

www.zoneregeling.nl/heatmiser/netmonitor-handleiding.pdf (Netmonitor User Manual) product

www.vulncheck.com/...tmiser-netmonitor-hardcoded-credentials (VulnCheck Advisory: Heatmiser Netmonitor 3.03 - Hardcoded Credentials) third-party-advisory

cve.org (CVE-2019-25322)

nvd.nist.gov (CVE-2019-25322)

Download JSON