Bitdefender - January 11, 2024 Vulnerabilities identified in Bosch BCC100 Thermostat https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-bosch-bcc100-thermostat/ Read there more.
That vulnerability requires the "attacker" to be on the same network. My solution to having a smart home is to give the devices ONLY LAN but not WAN and lock it all down in the router. THEN ---- > I use my Android and my personally setup VPN tunnel to join my LAN from anywhere in the world so I can always control the devices ---- BUT ----- only via LAN and never WAN. Makes sense I hope. Also, realize most internet users probably could not even read this post and understand the concept. Most of us here do though, so just a suggestion.