Your Bosch smart thermostat may not be as smart as you thought. This vulnerability allows hackers to install malicious updates and more, so patch now

Your Bosch smart thermostat could be hacked and used by threat actors for a wide range of malicious activities, researchers warn.

Cybersecurity experts from Bitdefender have published a new one report in which they discovered in detail a vulnerability in the Bosch BCC100 thermostat for versions SW 1.7.0 – HD 4.13.22. In the report, they said that the device has two microcontrollers, one that provides Wi-Fi functionality and one that provides the main function of the thermostat. The one with the Wi-Fi functionality listens to TCP port 8899 on LAN and mirrors any message received on that port directly to the main microcontroller, via the UART data bus.