{"id":79138,"date":"2026-06-01T14:46:24","date_gmt":"2026-06-01T11:16:24","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-25599-missing-authentication-and-clear-text-data-transmission-affecting-orca-heat-pumps\/"},"modified":"2026-06-01T14:46:24","modified_gmt":"2026-06-01T11:16:24","slug":"cve-2026-25599-missing-authentication-and-clear-text-data-transmission-affecting-orca-heat-pumps","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-25599-missing-authentication-and-clear-text-data-transmission-affecting-orca-heat-pumps\/","title":{"rendered":"CVE-2026-25599 &#8211; Missing authentication and clear\u2011text data transmission affecting Orca heat pumps"},"content":{"rendered":"<p>CVE ID :CVE-2026-25599<\/p>\n<p>  Published : June 1, 2026, 11:16 a.m. | 1\u00a0hour, 16\u00a0minutes ago<\/p>\n<p>  Description :Missing authentication and clear\u2011text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump\u2019s web control interface.\u00a0Older Orca heat pump devices communicating with the Orca server over an<br \/>\nunencrypted and unauthenticated HTTP connection on a non-secure port specifically enable an<br \/>\n attacker to impersonate a legitimate device and inject malicious<br \/>\npayloads. This enables the insertion of harmful code directly<br \/>\n into the Orca user portal, potentially compromising user accounts,<br \/>\nexposing sensitive information, and allowing further unauthorized<br \/>\nactions within the portal.<\/p>\n<p>  Severity: 6.3 | MEDIUM<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-25599 Published : June 1, 2026, 11:16 a.m. | 1\u00a0hour, 16\u00a0minutes ago Description :Missing authentication and clear\u2011text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump\u2019s web control &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-79138","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79138","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=79138"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79138\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=79138"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=79138"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=79138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}