Your Bosch smart thermostat may not be as smart as you thought – this security flaw could allow hackers to install malicious updates and more – so patch now

Researchers have warned that your Bosch smart thermostat can be hacked and used by threat actors for a wide variety of malicious activities.

Cybersecurity experts at Bitdefender have published a new report detailing the discovery of a vulnerability in the Bosch BCC100 thermostat for versions SW 1.7.0 – HD 4.13.22. In the report, they said that the device has two microcontrollers, one that provides Wi-Fi functionality and another that provides the main thermostat function. The one with Wi-Fi functionality listens to TCP port 8899 on the LAN and reflects any messages received on that port directly to the main microcontroller, via the UART data bus.