PT-2026-20283 · Honeywell · Honeywell Cctv Products

Souvik Kandar

·

Published

2026-02-17

·

Updated

2026-02-19

·

CVE-2026-1670

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Honeywell CCTV products (affected versions not specified)
Description The affected products are vulnerable to exposure of an unauthenticated API endpoint. This allows a remote attacker to change the recovery email address associated with the "forgot password" functionality. Successful exploitation could lead to account takeover and unauthorized access to Honeywell camera feeds. The systems are widely deployed in commercial and critical infrastructure environments, potentially compromising physical security visibility. The API endpoint allows manipulation of the password recovery flow without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-1670

Affected Products

Honeywell Cctv Products