CVE-2026-3611 details a critical authentication bypass vulnerability affecting the Honeywell IQ4x building management controller. In its factory-default configuration, the device exposes its full web-based HMI without authentication, allowing an unauthenticated remote attacker to create an administrative account. This flaw is rated 10.0 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), enabling full read/write privileges and potentially locking out legitimate operators. Currently, there is no evidence of active exploitation, nor is public exploit code available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.30CPE matchmatch criteria | cpe:2.3:o:honeywell:iq4e_firmware:*:*:*:*:*:*:*:* | ||
< 3.30CPE matchmatch criteria | cpe:2.3:o:honeywell:iq412_firmware:*:*:*:*:*:*:*:* | ||
< 3.30CPE matchmatch criteria | cpe:2.3:o:honeywell:iq422_firmware:*:*:*:*:*:*:*:* | ||
< 3.30CPE matchmatch criteria | cpe:2.3:o:honeywell:iq4nc_firmware:*:*:*:*:*:*:*:* | ||
< 3.30CPE matchmatch criteria | cpe:2.3:o:honeywell:iq41x_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Honeywell IQ4x Authentication Bypass (CVE-2026-3611)
Mar 16, 2026Honeywell IQ4x Authentication Bypass (CVE-2026-3611)
Mar 16, 2026Honeywell IQ4x Authentication Bypass (CVE-2026-3611)
Mar 16, 2026