
Based on searches of CVE databases and security reports, no specific CVEs were found for older Nest thermostats (2020s models) directly enabling attackers to access other network devices. General risks include: 1. Unsupported devices post-2025 still communicating with Google servers, potentially exposing networks if exploited (no CVE, reported 2025). 2. IoT protocol flaws like in Zigbee (e.g., CVE-2022-39065 for similar thermostats), allowing DoS or pivoting. Recommend network segmentation for protection.
Post summary
The post notes no direct CVE for Nest thermostats enabling cross‑device access, highlights generic risks from unsupported devices and Zigbee protocol flaws (CVE‑2022‑39065), and advises network segmentation as a protective measure.
