Cyber Security News

CISA Warns of Honeywell CCTV Products Vulnerability Leads to Account Takeovers

A critical advisory warning regarding a severe vulnerability affecting Honeywell CCTV products, published on February 17, 2026, under advisory ICSA-26-048-04.

The alert details a high-severity security flaw that could allow malicious actors to completely hijack user accounts and gain unauthorized access to sensitive camera feeds.

The vulnerability has been assigned a CVSS v3 score of 9.8, categorizing it as critical. The specific vulnerability, CVE-2026-1670, is a missing authentication issue affecting a critical function.

The flaw allows an unauthenticated attacker to modify the password recovery email address associated with the device without requiring prior login credentials.

CVE IDCVSS ScoreDescription
CVE-2026-16709.8Missing Authentication for Critical Function allowing unauthenticated recovery email changes.

Once the recovery email has been changed to an address controlled by the attacker, they can initiate a password reset to take over the administrative account.

This level of access not only compromises the video feeds but could also serve as a pivot point for further network compromise within the facility. The issue affects multiple versions of Honeywell’s IP and PTZ camera lines.

Product NameAffected Version
I-HIB2PI-UL 2MP IP6.1.22.1216
SMB NDAA MVO-3WDR_2MP_32M_PTZ_v2.0
PTZ WDR 2MP 32MWDR_2MP_32M_PTZ_v2.0
25M IPCWDR_2MP_32M_PTZ_v2.0

Security researcher Souvik Kandar has been credited with discovering and reporting this vulnerability to CISA. The affected equipment is deployed worldwide, primarily within the commercial facilities sector.

CISA has not reported any known public exploitation of this vulnerability at the time of publication. However, immediate action is recommended due to the ease of exploitation.

Administrators are advised to minimize network exposure for all control system devices, ensuring they are never directly accessible from the open Internet.

Control system networks should be located behind firewalls and isolated from business networks to prevent lateral movement.

For organizations requiring remote access, CISA suggests using secure methods such as Virtual Private Networks (VPNs), while ensuring the VPN devices themselves are updated to the latest versions.

Users are also encouraged to implement social engineering defenses, as attackers often use phishing to gain initial entry before exploiting internal vulnerabilities.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago