Executive brief
Honeywell IQ4 series building management controllers, which manage critical infrastructure like heating and cooling, are vulnerable to complete unauthorized takeover in their default configuration. Because the devices ship without security enabled, any person who can reach the controller over the network can create their own administrative account. This allows an attacker to change building settings, view sensitive data, or lock out legitimate operators entirely, potentially disrupting facility operations.
Technical details
The Honeywell IQ4 series controllers (IQ4E, IQ412, IQ422, IQ4NC, IQ41x) suffer from a missing authentication vulnerability (CWE-306) in their factory-default state. By design, the system operates in a 'System Guest' context (level 100) with full read/write privileges until a user module is manually configured. An unauthenticated remote attacker can access the 'U.htm' page to create a new administrative account, which dynamically enables the user module and enforces authentication using the attacker's credentials. This results in a complete compromise of the controller and a permanent lockout of legitimate administrators. The issue is resolved in firmware version 3.30 and later, which forces the creation of a user module during commissioning.
Affected products
- Honeywell IQ4E Firmware < 3.30
- Honeywell IQ412 Firmware < 3.30
- Honeywell IQ422 Firmware < 3.30
- Honeywell IQ4NC Firmware < 3.30
- Honeywell IQ41x Firmware < 3.30
Timeline
- 2026-03-10: advisory: Initial CISA advisory release
- 2026-03-12: disclosed: CVE published to NVD
- 2026-03-26: patched: Update A released with revised mitigation and version details