ZDI-26-160: (Pwn2Own) Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ed25519signopen function. The issue results from improper verification of a cryptographic signature. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2026-3562.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-160?
ZDI-26-160 is considered a critical vulnerability due to its potential to allow arbitrary code execution without authentication.
How do I fix ZDI-26-160?
To fix ZDI-26-160, apply the latest firmware update provided by Philips for the Hue Bridge.
Who is affected by ZDI-26-160?
ZDI-26-160 affects all installations of Philips Hue Bridge that do not have the latest firmware installed.
Can ZDI-26-160 be exploited remotely?
Yes, ZDI-26-160 can be exploited by network-adjacent attackers, meaning they need to be on the same network to execute the attack.
What type of code can be executed through ZDI-26-160?
ZDI-26-160 allows attackers to execute arbitrary code, which can lead to full system compromise of the Philips Hue Bridge.