216.73.216.233

CVE-2026-3611

· Published 12/03/2026 21:16 · Modified 13/03/2026 20:06

Labels: CVE-2026-3611 2026-03-12CVE-2026-3611CWE-306[email protected]

Essential information

Published
12/03/2026 21:16
Modified
13/03/2026 20:06
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
honeywell / iq4x cpe:2.3:a:honeywell:iq4x:*:*:*:*:*:*:*:*

References