Some thermostats have built-in web servers.
http
other than https
: 1) handshake encryption on Thermostat might be expensive in terms of CPU; 2) how to update web certificates on Theormostat (company doesn't want users to replace thermostats in every 5 years)?
Turn off thermostats for a long time, then turn on thermostats possibly just coming back from vacation.
Overall, it's hard to know all the threats. We can see what is made available, and ask who might want it.
Check "gold standard" (Au): Authentication, Authorization, Audit.