← Vulnerability feed

Vulnerability record · CVE-2026-3555 · published 16 March 2026

CVE-2026-3555: Philips hue bridge v2 firmware heap-based buffer overflow vulnerability

Philips · Hue Bridge V2 Firmware

Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. User interaction is required to exploit this vulnerability in that the user must initiate the device pairing process. The specific flaw exists within the handling of custom Zigbee ZCL frames in the Model Info download functionality. The issue results from the lack of proper validation of the size of data prior to copying it to a fixed-size heap buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-28276.

8.0 CVSS 3.0 High EPSS 0.37% · top 71.5% CWE-122 · Heap-based buffer overflow
8.0CVSS 3.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. User interaction is required to exploit this vulnerability in that the user must initiate the device pairing process. The specific flaw exists within the handling of custom Zigbee ZCL frames in the Model Info download functionality. The issue results from the lack of proper validation of the size of data prior to copying it to a fixed-size heap buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-28276.

CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-3555 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-3560Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-…EPSS 0.54%8.8CVE-2026-3562Philips hue bridge v2 firmware improper verification of cryptographic signature vulnerabilityPhilips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to…EPSS 0.31%8.8CVE-2026-3556Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta…EPSS 0.54%8.1CVE-2026-3559Philips hue bridge v2 firmware vulnerabilityPhilips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers …EPSS 0.39%8.1CVE-2026-3558Philips hue bridge v2 firmware missing authentication for critical function vulnerabilityPhilips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …EPSS 0.40%8.0CVE-2026-3561Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent …EPSS 0.58%8.0CVE-2026-3557Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …EPSS 0.58%7.9CVE-2020-6007Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during t…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2026-3555), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.