HIGHVulnerability
CVE-2026-73669
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010.
Properties
- severity
- HIGH
- score
- 7.3
- cve_id
- CVE-2026-73669
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- published_at
- 2026-08-13T20:17:30.440
- last_modified
- 2026-08-18T21:18:18.170
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Missing Authentication for Critical Function
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph