CVE-2026-1670 describes a critical vulnerability affecting Honeywell HIB2PI and HDZ Series CCTV cameras, stemming from an unauthenticated API endpoint exposure. This flaw allows an attacker to remotely alter the "forgot password" recovery email address, potentially leading to full account compromise. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 23 mentions and 3 media articles, indicating a high level of awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Honeywell | 25M IPC | WDR_2MP_32M_PTZ_v2.0CNA affecteddefault unaffected | |
| Honeywell | I-HIB2PI-UL 2MP IP | 6.1.22.1216CNA affecteddefault unaffected | |
| Honeywell | PTZ WDR 2MP 32M | WDR_2MP_32M_PTZ_v2.0CNA affecteddefault unaffected | |
| Honeywell | SMB NDAA MVO-3 | WDR_2MP_32M_PTZ_v2.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.