CVE-2026-73669
Received Received - Intake

Unauthenticated MQTT Access in Philips Hue Bridge Pro Firmware

Vulnerability report for CVE-2026-73669, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker (v2.0.22) that listens on all network interfaces with anonymous access enabled and no firewall restriction. An attacker with access to the Bridge's network can read device data and control connected lights.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
signify philips_hue_bridge_pro to 2.0.22 (inc)
mosquitto mosquitto 2.0.22
signify philips_hue_bridge_pro to 2071401010 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability involves the Signify Philips Hue Bridge Pro firmware which includes a Mosquitto MQTT broker (version 2.0.22) configured to listen on all network interfaces with anonymous access enabled and no firewall restrictions. This allows an attacker on the same network to read data from connected devices and control smart lights without authentication.

Detection Guidance

Check if your Philips Hue Bridge Pro firmware is outdated by verifying the version in the Hue app under Settings > Software update. Use network scanning tools like nmap to detect if the Mosquitto MQTT broker (port 1883) is exposed on all interfaces with anonymous access enabled.

Impact Analysis

An attacker could gain unauthorized access to your network via the Hue Bridge Pro and manipulate connected lights or read sensitive device data. This could lead to privacy breaches, unauthorized control of home automation systems, or disruption of smart home functionality.

Compliance Impact

The vulnerability allows unauthorized access to device data and control of connected lights due to an exposed MQTT broker with no authentication. This could lead to unauthorized data collection or manipulation, potentially violating data protection requirements under GDPR and HIPAA if personal or health-related data is involved.

Mitigation Strategies

Enable automatic updates in the Philips Hue app to ensure the latest firmware is installed. If automatic updates were disabled, manually update to firmware version 2071401010 or later via the Hue app.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73669. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart