Bosch Smart Thermostat Feels the Heat From Firmware Bug
ID: 0bbada9e-4994-5e9d-b254-72913e29bb60
STIX ID: report--0bbada9e-4994-5e9d-b254-72913e29bb60
Feed Name: Dark Reading
A critical vulnerability (CVE-2023-49722) has been disclosed in Bosch BCC100 thermostats affecting firmware versions 1.7.0 – HD 4.13.22; the flaw in the device Wi‑Fi microcontroller can allow a local attacker to execute arbitrary commands, replace the operating system with a rogue firmware or brick the device, enabling backdoors and potential network pivoting. Bitdefender reported the issue and Bosch has issued patches; recommended mitigations include applying firmware updates and isolating IoT devices on segmented networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
