ZDI-26-156: (Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the HomeKit Accessory Protocol service, which listens on TCP port 8080 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-3558.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-156?
The severity of ZDI-26-156 is considered high due to the potential for unauthorized access to the Philips Hue Bridge.
How do I fix ZDI-26-156?
To fix ZDI-26-156, update the Philips Hue Bridge to the latest firmware provided by Philips.
What type of attacks can ZDI-26-156 facilitate?
ZDI-26-156 can facilitate network-adjacent attacks allowing unauthorized users to interact with the Philips Hue Bridge.
Which devices are affected by ZDI-26-156?
The devices affected by ZDI-26-156 are Philips Hue Bridges that are operating without the latest security updates.
Is authentication required to exploit ZDI-26-156?
No, authentication is not required to exploit ZDI-26-156, making it particularly dangerous.