CVE-2026-3611 Details
Description
The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.
A vulnerability exists in the Honeywell IQ4x building management controller, where the web-based human-machine interface (HMI) is accessible without authentication in the default factory configuration. This vulnerability affects several controller models, including IQ4E, IQ412, IQ422, IQ4NC, IQ41x, IQ3, and IQECO, all running firmware versions 3.50.3.44 prior to 4.36_build_4.3.7.9. In this unprotected state, the system operates under a System Guest context, allowing read/write access to anyone who can reach the HTTP interface. Authentication is only required after a web user is created, which can be done through an unprotected URL. This exploitation enables the creation of an admin account, potentially locking out legitimate users from the system.
Honeywell is aware of the issue but has not released a fix. For more information, contact Honeywell directly.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-03.json | [email protected] | Issue Tracking |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-03 | [email protected] | Third Party AdvisoryUS Government Resource |
| https://www.honeywell.com/us/en/contact | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| honeywell iq4e firmware | < 3.30 |
CPE
Remediation
| |
| honeywell iq4e | All versions |
CPE
Remediation
| |
| honeywell iq412 firmware | < 3.30 |
CPE
Remediation
| |
| honeywell iq412 | All versions |
CPE
Remediation
| |
| honeywell iq422 firmware | < 3.30 |
CPE
Remediation
| |
| honeywell iq422 | All versions |
CPE
Remediation
| |
| honeywell iq4nc firmware | < 3.30 |
CPE
Remediation
| |
| honeywell iq4nc | All versions |
CPE
Remediation
| |
| honeywell iq41x firmware | < 3.30 |
CPE
Remediation
| |
| honeywell iq41x | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Mar 12, 2026 | New CVE Received | [email protected] |