Thousands of Honeywell building-management controllers may be accessible online with no login required, exposing web-based controls that can be abused to make unauthorized changes and trigger operator lockouts.
Zero Science Lab has published advisory ZSL-2026-5979 (released 02 March 2026) detailing an unauthenticated access issue affecting Honeywell Trend IQ4xx BMS controllers in factory-default configuration.
The IQ4 (Trend IQ4) family is widely used for building automation and HVAC control, supporting Ethernet/TCP/IP and BACnet/IP, and can scale up to large I/O configurations in commercial environments.
According to the advisory, when no “user module” is configured, the controller’s full Web HMI is exposed without authentication by design.
In this state, the system operates under a high-privilege “System User (level 100)” context, meaning that anyone who can reach the HTTP interface can gain read/write access through the Web HMI.
A key risk is that authentication is only enforced after a web user is created via the U.htm page, which dynamically enables the user module.
According to the Zero Science Lab advisory, the user-creation function is accessible prior to authentication, allowing a remote attacker to create a new administrative account and enable login with attacker-controlled credentials.
This allows the attacker to take over access controls and effectively lock out legitimate operators, both local and web-based.
An advisory also notes a hidden “Diagnostics Overview” endpoint accessible at/^.htm or /%5E.htm, which increases the exposed functionality for an attacker who can access the interface.
Zero Science Lab rates the issue at 5/5 risk, citing impacts including security bypass, system access, and denial-of-service conditions.
A proof-of-concept script (trendhmi.py) has been publicly referenced, and a coordination path includes CERT/CC case VU#854120, with CISA requesting a vendor evaluation.
Honeywell PSIRT reportedly responded that IQ4 is intended for on-premises use and not for direct Internet exposure, and recommended qualified installation and adherence to the documentation.
Affected products listed include IQ4E, IQ412, IQ422, IQ4NC, IQ41x, IQ3, and IQECO, with impacted firmware versions including 4.36 (build 4.3.7.9), 4.34 (build 4.3.5.14), 3.52 (build 3.5.3.15), 3.50, and 3.44.
Mitigation and detection
- Remove direct Internet exposure: block inbound access to controller web interfaces at the perimeter, restrict management to VPN and allowlists, and allow only VPN traffic.
- Enable controller security properly: create and enforce user modules, then validate that unauthenticated access to Web HMI and U.htm is not possible.
- Segment OT/BMS networks: isolate controllers from flat corporate networks and remote-access jump paths
- Monitor for suspicious HTTP activity: requests to U.htm, /^.htm, or /%5E.htm, and unexpected creation of new admin users
- Inventory and audit: identify Trend IQ4xx devices, confirm firmware, and review access-rights configuration against Honeywell best-practice guidance (TP201331)
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
