← Back to browse · API

CVE-2026-3611

Severity
CRITICAL
CVSS
10.0
EPSS
0.05503
Risk score
41.93
CISA KEV
No
PoC
Yes
Published
2026-03-12
Modified
2026-03-30
First seen
2026-08-07
Aliases
EUVD-2026-11706, GHSA-3P4G-VG78-JQRV
Products
Honeywell:IQ3 v3.50_3.44 ≤4.36 (build 4.3.7.9), Honeywell:IQ412 v3.50_3.44 ≤4.36 (build 4.3.7.9), Honeywell:IQ41x v3.50_3.44 ≤4.36 (build 4.3.7.9), Honeywell:IQ422 v3.50_3.44 ≤4.36 (build 4.3.7.9), Honeywell:IQ4E v3.50_3.44 ≤4.36 (build 4.3.7.9), Honeywell:IQ4NC v3.50_3.44 ≤4.36 (build 4.3.7.9), Honeywell:IQECO v3.50_3.44 ≤4.36 (build 4.3.7.9)
Sources
euvd EUVD-2026-11706
github fb654555ad754ed4fb7bdc8e|CVE-2026-3611

Description

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.

References