CVE-2026-73669

Summary

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010.

Affected Software

VendorProductVersion RangeStatus
SignifyPhilips Hue Bridge Pro0 < 1.77.2071318010affected
SignifyPhilips Hue Bridge Pro1.77.2071318010unaffected

Weaknesses

  • CWE-306: CWE-306 Missing Authentication for Critical Function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References