logo

Honeywell Controllers Widely Exposed Without Authentication

ID: e26a32fd-2837-5ac3-82c5-748610dcd8e0

STIX ID: report--e26a32fd-2837-5ac3-82c5-748610dcd8e0

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Divya

...
...

Zero Science Lab disclosed a critical default-configuration vulnerability (ZSL-2026-5979) in Honeywell Trend IQ4xx BMS controllers that expose the full web HMI without authentication, allowing an unauthenticated attacker to create an administrator account and take complete control of devices; a proof-of-concept script (trendhmi.py) was published, affected firmware versions are listed, and researchers escalated the issue to CERT/CC and CISA while Honeywell had not yet issued a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.