cvedb.io
CVE-2026-3611
CRITICAL · CVSS 10
EPSS exploitation probability: 0%
Published 2026-03-12T21:16:27.693 · Last modified 2026-06-17T10:43:52.107

Summary

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configurat

Affected products

honeywell — iq4e_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when honeywell ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.