Hackers can hijack your Bosch Thermostat and Install Malware
ID: 31dacdee-c0df-5f64-98b3-9d47706c47d6
STIX ID: report--31dacdee-c0df-5f64-98b3-9d47706c47d6
Feed Name: HackRead
Bitdefender Labs disclosed a vulnerability (CVE-2023-49722) in the Bosch BCC100 thermostat (affected versions 1.7.0 – HD 4.13.22) that allows an attacker to forge cloud/update responses and push rogue firmware via the Wi‑Fi chip’s TCP/WebSocket interface—potentially enabling remote manipulation of settings and installation of malware; Bitdefender responsibly disclosed the issue in January 2024 and Bosch issued an advisory and started remediation. Users are advised to update firmware, change default passwords, limit internet exposure, and use network controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
