Executive brief
Honeywell S35 series security cameras contain a vulnerability that allows unauthorized individuals to view the device's audit logs. These logs track system activity and may contain sensitive information about the camera's operation or user interactions. An attacker could exploit this to gather intelligence about the security environment without needing a password.
Technical details
A vulnerability in the Honeywell S35 Series 3M/5M/8M/PinHole Cameras (versions up to HC5.26.1.14.20260207) allows for the disclosure of audit logs to unauthenticated actors. Categorized as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), the flaw stems from improper access controls on the log retrieval mechanism. A remote attacker can access these logs over the network without providing credentials. This could lead to the exposure of sensitive operational data or metadata contained within the system logs. Honeywell recommends upgrading to version HC5.26.1.16.20260207 or later to remediate the issue.
Affected products
- Honeywell S35 Series 3M/5M/8M/PinHole Cameras All versions prior to and including HC5.26.1.14.20260207
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory