Description
Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service or offering (S35 Pinhole/Kit Camera to version 2025.08.28, S35 AI Fisheye & Dual Sensor/Micro Dome/Full Color Eyeball & Bullet Camera to version 2025.08.22, S35 Thermal Camera to version 2025.08.26).
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
CWE-668 Exposure of Resource to Wrong Sphere
Product status
2022.02.28 (date) before 2025.08.28
2024.08.10 (date) before 2025.08.22
2024.10.21 (date) before 2025.08.26
References
www.honeywell.com/us/en/product-security