Honeywell Controllers Widely Exposed Without Authentication
ID: e26a32fd-2837-5ac3-82c5-748610dcd8e0
STIX ID: report--e26a32fd-2837-5ac3-82c5-748610dcd8e0
Feed Name: GBHackers
Threat Score
Zero Science Lab disclosed a critical default-configuration vulnerability (ZSL-2026-5979) in Honeywell Trend IQ4xx BMS controllers that expose the full web HMI without authentication, allowing an unauthenticated attacker to create an administrator account and take complete control of devices; a proof-of-concept script (trendhmi.py) was published, affected firmware versions are listed, and researchers escalated the issue to CERT/CC and CISA while Honeywell had not yet issued a patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
