Security Advisory

CVE-2026-73669

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-13 19:00:05
Last updated 2026-08-18 20:28:10
Assigner cisa-cg
CVSS score 7.3
State PUBLISHED

Description

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010.