CVE-2026-1670

CRITICAL

Affected Products - Info Disclosure

Title source: llm
STIX 2.1

Description

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

Scores

CVSS v3 9.8
EPSS 0.0003
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (4)
Honeywell/25M IPC WDR_2MP_32M_PTZ_v2.0
Honeywell/I-HIB2PI-UL 2MP IP 6.1.22.1216
Honeywell/PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0
Honeywell/SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0
Published Feb 17, 2026
Tracked Since Feb 18, 2026