ID

VAR-202603-0913


CVE

CVE-2026-3555


TITLE

(Pwn2Own) Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability

Trust: 0.7

sources: ZDI: ZDI-26-153

DESCRIPTION

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. User interaction is required to exploit this vulnerability in that the user must initiate the device pairing process.The specific flaw exists within the handling of custom Zigbee ZCL frames in the Model Info download functionality. The issue results from the lack of proper validation of the size of data prior to copying it to a fixed-size heap buffer. An attacker can leverage this vulnerability to execute code in the context of the device.

Trust: 0.7

sources: ZDI: ZDI-26-153

AFFECTED PRODUCTS

vendor:philipsmodel:hue bridgescope: - version: -

Trust: 0.7

sources: ZDI: ZDI-26-153

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: CVE-2026-3555
value: HIGH

Trust: 0.7

ZDI: CVE-2026-3555
baseSeverity: HIGH
baseScore: 8.0
vectorString: AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-26-153

PATCH

title:Fixed in Bridge v2 Software version 1975170000url:https://www.philips-hue.com/en-ca/support/release-notes/bridge

Trust: 0.7

sources: ZDI: ZDI-26-153

EXTERNAL IDS

db:ZDI_CANid:ZDI-CAN-28276

Trust: 0.7

db:NVDid:CVE-2026-3555

Trust: 0.7

db:ZDIid:ZDI-26-153

Trust: 0.7

sources: ZDI: ZDI-26-153

REFERENCES

url:https://www.philips-hue.com/en-ca/support/release-notes/bridge

Trust: 0.7

sources: ZDI: ZDI-26-153

CREDITS

Mehdi Talbi, Matthieu Breuil, Théo Gordyjan from @Synacktiv

Trust: 0.7

sources: ZDI: ZDI-26-153

SOURCES

db:ZDIid:ZDI-26-153

LAST UPDATE DATE

2026-03-09T23:53:52.758000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-26-153date:2026-03-06T00:00:00

SOURCES RELEASE DATE

db:ZDIid:ZDI-26-153date:2026-03-06T00:00:00