Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1670

37
FAUCET Score

CVE-2026-1670 describes a critical vulnerability affecting Honeywell HIB2PI and HDZ Series CCTV cameras, stemming from an unauthenticated API endpoint exposure. This flaw allows an attacker to remotely alter the "forgot password" recovery email address, potentially leading to full account compromise. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 23 mentions and 3 media articles, indicating a high level of awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
Honeywell25M IPC
WDR_2MP_32M_PTZ_v2.0CNA affecteddefault unaffected
HoneywellI-HIB2PI-UL 2MP IP
6.1.22.1216CNA affecteddefault unaffected
HoneywellPTZ WDR 2MP 32M
WDR_2MP_32M_PTZ_v2.0CNA affecteddefault unaffected
HoneywellSMB NDAA MVO-3
WDR_2MP_32M_PTZ_v2.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.83%
Probability of exploitation in next 30 days
EPSS Percentile
53.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0083 is in the 38th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

coollabspatch availablevia llm_extracted
linuxpatch availablevia llm_extracted
View patch
power_bivendor investigatingvia llm_extracted

Vendor Advisories (3)

coollabsllm-coollabs-f1831578b67829c1CRITICAL

Vulnerabilities in HIB2PI CCTV Cameras

Feb 23, 2026
linuxllm-linux-5255a103e38e37d7CRITICAL

Vulnerabilities in HIB2PI CCTV Cameras

Feb 23, 2026
power_billm-power_bi-ea767d5ea145b8acCRITICAL

Vulnerabilities in HIB2PI CCTV Cameras

Feb 23, 2026

References

github.com / cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-048-04.json
cisa.gov / news-events/ics-advisories/icsa-26-048-04
honeywell.com / us/en/contact/support