CVE Feed

    Dashboard / CVE / CVE-2026-3611

    CVE-2026-3611

    The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.

    Published:Mar 12, 2026
    Last Modified:Jun 5, 2026
    EPS:Mar 12, 2026
    EPSS Score:0.00242
    CVSS Score:10

    Affected Products

    Vendor
    Honeywell
    Product
    Iq3
    Vendor
    Honeywell
    Product
    Iq412
    Vendor
    Honeywell
    Product
    Iq412 Firmware
    Vendor
    Honeywell
    Product
    Iq41x
    Vendor
    Honeywell
    Product
    Iq41x Firmware
    Vendor
    Honeywell
    Product
    Iq422
    Vendor
    Honeywell
    Product
    Iq422 Firmware
    Vendor
    Honeywell
    Product
    Iq4e
    Vendor
    Honeywell
    Product
    Iq4e Firmware
    Vendor
    Honeywell
    Product
    Iq4nc
    Vendor
    Honeywell
    Product
    Iq4nc Firmware
    Vendor
    Honeywell
    Product
    Iqeco

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High