CVE-2026-1670
CRITICAL
9.8
CVSS 3.1
Description
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (4)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Honeywell | 25M IPC | — | WDR_2MP_32M_PTZ_v2.0 |
| Honeywell | I-HIB2PI-UL 2MP IP | — | 6.1.22.1216 |
| Honeywell | PTZ WDR 2MP 32M | — | WDR_2MP_32M_PTZ_v2.0 |
| Honeywell | SMB NDAA MVO-3 | — | WDR_2MP_32M_PTZ_v2.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-306 | cna | CWE-306 Missing Authentication for Critical Function |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (3)