CVE-2017-14263
Honeywell
- Published
- 11 September 2017
- Last modified
- 17 June 2026
- CVSS
- 8.1 v3.0
- Severity
- high
- EPSS
- 3.7% (89th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- CWE-384
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 3.7% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| Enterprise DVR | Honeywell | Digital video recorder | — |
| Maxpro NVR Hybrid Se | Honeywell | Network video recorder | — |
| Maxpro NVR Hybrid Xe | Honeywell | Network video recorder | — |
| Maxpro NVR Pe | Honeywell | Network video recorder | <= 5.6 |
| Maxpro NVR Se | Honeywell | Network video recorder | <= 5.6 |
| Maxpro NVR Xe | Honeywell | Network video recorder | <= 5.6 |
References
- https://github.com/zzz66686/Honeywell_NVR_vul third-party
- https://github.com/zzz66686/Honeywell_NVR_vul third-party
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.