Critical Authentication Bypass in Honeywell IQ4x BMS Controllers (CVE‑2026‑3611) Threatens Facility Operations
What It Is – A missing‑authentication flaw in the web‑based HMI of Honeywell’s IQ4x building‑management system (BMS) controllers allows an unauthenticated attacker to read or modify controller settings, command HVAC, lighting, fire‑safety subsystems, or trigger a denial‑of‑service.
Exploitability – The vulnerability is publicly disclosed (CVE‑2026‑3611) with a CVSS 3.1 base score of 10.0 (Critical). No public exploit code has been released, but the attack requires only network access to the controller’s default web interface, making exploitation trivial in environments where default configurations remain unchanged.
Affected Products – Honeywell IQ4x series controllers (IQ4E, IQ412, IQ422, IQ4NC, IQ41x, IQ3, IQECO) running firmware ≥ v3.50 & < 4.36 (build 4.3.7.9).
TPRM Impact –
- Facilities that rely on these controllers (commercial real‑estate, hospitals, manufacturing plants, government sites) inherit a direct supply‑chain risk.
- A compromised BMS can disrupt critical environmental controls, fire‑suppression systems, and occupant safety, leading to operational downtime and potential regulatory violations.
Recommended Actions –
- Inventory all Honeywell IQ4x controllers and verify firmware versions.
- Upgrade to Honeywell‑provided firmware ≥ 4.36 (or later) that enforces authentication.
- Disable the factory‑default web HMI or restrict it to a segmented management VLAN.
- Implement network‑level access controls (firewall, ACLs) to limit inbound traffic to trusted management hosts.
- Conduct a penetration test of the BMS network segment to confirm remediation.
Source: CISA Advisory – ICSA‑26‑069‑03