# Exploit Title: Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery # Dork: intitle:"Heatmiser Wifi Thermostat" & you can use shodan # Date: 2019-01-09 # Exploit Author: sajjadbnd # Vendor Lnk: https://www.heatmiser.com/en/ # Product Link: https://www.heatmiser.com/en/wireless-thermostats/ # Tested on: Heatmiser Version 1.7 # CVE: N/A # [+] CSRF: Change Admin Username and Password
Name: Password: Confirm User Password: