CVE-2026-1670
Honeywell CCTV Products Missing Authentication for Critical Function
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Honeywell · 25M IPCHoneywell · I-HIB2PI-UL 2MP IPHoneywell · PTZ WDR 2MP 32MHoneywell · SMB NDAA MVO-3Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →