CVE-2026-3611

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:honeywell:iq4e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:iq4e:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:honeywell:iq412_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:iq412:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:honeywell:iq422_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:iq422:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:honeywell:iq4nc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:iq4nc:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:honeywell:iq41x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:honeywell:iq41x:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-12 21:16

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3611

Mitre link : CVE-2026-3611

CVE.ORG link : CVE-2026-3611


JSON object : View

Products Affected

honeywell

  • iq41x
  • iq4e
  • iq4nc
  • iq412_firmware
  • iq422_firmware
  • iq4e_firmware
  • iq4nc_firmware
  • iq412
  • iq422
  • iq41x_firmware
CWE
CWE-306

Missing Authentication for Critical Function