Impact
EQ‑3’s Eqiva CC‑RT‑BLE Bluetooth Smart Radiator Thermostat firmware versions up to 1.46 suffer from a missing authentication check that allows any nearby Bluetooth‑enabled device to establish a connection and issue commands, providing full control of the thermostat. The flaw is a classic example of CWE‑306, an authentication weakness. An attacker could alter temperature settings, read status information, or inject arbitrary commands, potentially leading to unauthorized temperature manipulation and privacy violations.
Affected Systems
EQ‑3’s Eqiva CC‑RT‑BLE Bluetooth Smart Radiator Thermostat, firmware versions up to 1.46.
Risk and Exploitability
The flaw has a CVSS score of 7.1 and an EPSS score of less than 1%. It is not listed in the CISA KEV catalog, indicating no confirmed exploitation yet. Exploitation requires proximity to the device’s Bluetooth radio and no special privileges; the attacker simply initiates a Bluetooth session to send commands. The low EPSS suggests that although the vector is simple, it is not widely exploited in the current threat landscape.
OpenCVE Enrichment