Skip to content
Honeywell Trend IQ4xx Controllers Exposed Online Without Authentication

Honeywell Trend IQ4xx Controllers Exposed Online Without Authentication

First seen 4 Mar 2026, 14:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Thousands of Honeywell Trend IQ4xx building-management controllers are accessible online without authentication, allowing unauthorized access to web-based controls. The vulnerability was disclosed by Zero Science Lab in advisory ZSL-2026-5979, which details the issue affecting devices in their factory-default configuration. The advisory was released on March 2, 2026, following months of research.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

Timeline

2026-03-02
Zero Science Lab released advisory ZSL-2026-5979
2026-03-04
Cybersecurity news articles published about the exposure

More articles in this cluster (2)

Following this threat?

Track Honeywell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed