CVE-2026-3562: (Pwn2Own) Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability
Philips Hue Bridge hkhap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the ed25519signopen function. The issue results from improper verification of a cryptographic signature. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-28480.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3562?
CVE-2026-3562 is considered critical due to its potential for arbitrary code execution by network-adjacent attackers.
How do I fix CVE-2026-3562?
To mitigate CVE-2026-3562, update your Philips Hue Bridge to the latest firmware version provided by Philips.
What are the main consequences of CVE-2026-3562?
The main consequences of CVE-2026-3562 include unauthorized access and the ability for attackers to execute arbitrary code on the affected device.
Which devices are affected by CVE-2026-3562?
CVE-2026-3562 affects all versions of the Philips Hue Bridge that utilize the hk_hap Ed25519 signature verification.
Is there a workaround for CVE-2026-3562 until a patch is available?
There are currently no known workarounds for CVE-2026-3562, so it is recommended to update your device as soon as a patch is released.