The Default Danger: Maximum 10.0 CVSS Vulnerability Leaves Honeywell IQ4x Controllers Wide Open
ID: 08624626-6583-5f0b-a7b3-0295dd78e92b
STIX ID: report--08624626-6583-5f0b-a7b3-0295dd78e92b
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-3611, CVSS 10.0) was disclosed in Honeywell IQ4x BMS controllers where the factory-default configuration exposes the full web-based HMI without authentication. If left unconfigured, attackers with network access can manipulate controller management settings, control building components, exfiltrate information, or cause DoS across multiple IQ4x models and affected firmware versions; administrators are advised to enforce robust authentication immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
