CVE-2026-73669
6.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Summary
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Signify | Philips Hue Bridge Pro | 0 < 1.77.2071318010 | affected |
| Signify | Philips Hue Bridge Pro | 1.77.2071318010 | unaffected |
Weaknesses
- CWE-306: CWE-306 Missing Authentication for Critical Function
References
- https://www.philips-hue.com/en-us/support/release-notes/bridge-pro
- https://www.philips-hue.com/en-us/support/security-advisory
- https://www.cve.org/CVERecord?id=CVE-2026-73669
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-225-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.