CVE-2026-73669 PUBLISHED

Philips Hue Bridge Pro MQTT broker missing authentication

Assigner: cisa-cg
Reserved: 13.08.2026 Published: 13.08.2026 Updated: 13.08.2026

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Signify
Product Philips Hue Bridge Pro
Versions Default: unknown
  • affected from 0 to 1.77.2071318010 (excl.)
  • Version 1.77.2071318010 is unaffected

Credits

  • Buğrahan KARAHAN

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE