Back to Feed
VulnerabilitiesMar 10, 2026

Honeywell IQ4x BMS Controller

A critical authentication vulnerability (CVSS 10.0) in Honeywell IQ4x BMS Controller firmware versions 3.50 through 4.36_build_4.3.7.9 allows unauthorized attackers to access management settings, control components, and cause denial-of-service without authentication. Honeywell has not yet released a patch and recommends network isolation and defensive measures until remediation is available.

Summary

A critical authentication vulnerability (CVSS 10.0) in Honeywell IQ4x BMS Controller firmware versions 3.50 through 4.36_build_4.3.7.9 allows unauthorized attackers to access management settings, control components, and cause denial-of-service without authentication. Honeywell has not yet released a patch and recommends network isolation and defensive measures until remediation is available.

Indicators of Compromise

  • cve — CWE-306