Authentication Bypass Vulnerability in Philips Hue Bridge by Philips
CVE-2026-3562
6.3MEDIUM
What is CVE-2026-3562?
The Philips Hue Bridge is susceptible to an authentication bypass vulnerability that allows attackers on the same network to execute arbitrary code. The flaw originates from improper verification of cryptographic signatures within the ed25519_sign_open function. This means that attackers can exploit the vulnerability without needing authentication, posing a significant risk to users of affected devices. Immediate action is recommended to secure networks against potential exploitation.
Affected Version(s)
Hue Bridge 1.73.1973146020