A serious flaw in certain Honeywell CCTV systems that permits illegal access to feeds or account hijacking is being warned about by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
The security flaw, identified by researcher Souvik Kanda and designated as CVE-2026-1670, is categorized as “missing authentication for critical function” and has a critical severity level of 9.8.
The vulnerability permits account takeover and unauthorized access to camera feeds by allowing an unauthenticated attacker to modify the recovery email address linked to a device account.
According to CISA, the impacted product has an unauthenticated API endpoint vulnerability that could enable an attacker to remotely modify the “forgot password recovery email address.”
The following models are affected by CVE-2026-1670 read more about Critical infra Honeywell CCTVs vulnerable to auth bypass flaw.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
