CVE-2026-1670: Honeywell 25m Ipc
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.
Affected products
- Honeywell 25m Ipc
- Honeywell I-HIB2PI-Ul 2mp IP: version 6.1.22.1216 only
- Honeywell Ptz Wdr 2mp 32m
- Honeywell SMB Ndaa Mvo-3
Published 2026-02-17. Last modified 2026-06-17.