AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-73669

MEDIUM · CVSS 6.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Signify Philips Hue Bridge Pro firmware is vulnerable due to the embedded Mosquitto MQTT broker (v2.0.22), which allows anonymous access and listens on all network interfaces without firewall restrictions. This vulnerability enables attackers on the same network to read device data and control connected lighting systems. Organizations utilizing Philips Hue Bridge Pro should prioritize addressing this issue to mitigate potential unauthorized access and control of their smart lighting infrastructure.

CVE
CVE-2026-73669
Severity
MEDIUM
CVSS
6.3
EPSS
0.21%

Original NVD Description

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights.