Impact
The vulnerability allows unauthenticated modification of the recovery email address through a public API endpoint, enabling an attacker to tamper with credential recovery procedures. This weakness corresponds to an authentication failure where no credentials are required to alter account‑related data.
Affected Systems
Affected Honeywell CCTV cameras and controllers include the 25 M IPC series, the I‑HIB2PI‑UL 2MP IP unit, the PTZ WDR 2MP 32M camera, and the SMB NDAA MVO‑3. Specific revision or firmware numbers are not listed in the CNA data, so the impact applies to all currently installed units of these product lines lacking the fix.
Risk and Exploitability
The CVSS score of 9.3 denotes a high‑severity flaw. The EPSS score of less than 1 % indicates that, at the time of analysis, the probability of public exploitation is low, yet the flaw remains a high‑value target because it requires no special privileges and can be carried out by any network actor that can reach the device. It is not yet listed in the CISA KEV catalog. Based on the description it is inferred that the vulnerable API endpoint is accessible over the network without authentication, which allows attackers to remotely alter recovery information and potentially hijack user accounts.
OpenCVE Enrichment