Auth bypass in Honeywell CCTV risks unauthorized feeds and account takeover

1 min read
Source: BleepingComputer
Auth bypass in Honeywell CCTV risks unauthorized feeds and account takeover
Photo: BleepingComputer
TL;DR Summary

CISA warns of a critical vulnerability (CVE-2026-1670) in multiple Honeywell CCTV models that allows an unauthenticated attacker to change the recovery email on a device account, enabling account takeover and unauthorized access to camera feeds; as of Feb 17 there were no known public exploits; mitigations include limiting network exposure, isolating devices behind firewalls, and using secure VPN remote access; Honeywell has not issued a public advisory and users should contact support for patch guidance.

Share this article

Reading Insights

Total Reads

0

Unique Readers

6

Time Saved

3 min

vs 4 min read

Condensed

89%

67675 words

Want the full story? Read the original article

Read on BleepingComputer