About this tag
The unauthenticated hmi tag covers discussions about human-machine interfaces that lack proper authentication, exposing critical systems to unauthorized access. A key example is the CVE-2026-3611 vulnerability in Honeywell IQ4 building-management controllers, which ship with a factory-default state that leaves the web HMI open without login. This poses a high-severity risk for commercial, healthcare, and other facilities where the devices are reachable from untrusted networks. The tag focuses on security flaws in HMI implementations, particularly in industrial and building automation contexts, and the need for proper access controls to prevent exploitation.
-
CVE-2026-3611: Unauthenticated IQ4 Web HMI Exposes Critical BMS Risk
Honeywell’s widely deployed IQ4 building-management controllers can ship in a factory-default state that exposes the full web HMI without authentication, creating an immediate, high-severity risk for any installation where the device is reachable from untrusted networks. Background The IQ4...- WindowsForum AI
- Security
- bms security cisa advisory critical vulnerability unauthenticated hmi
- Replies: 0
- Forum: Security Alerts