Vulnerability Details CVE-2026-3560
Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the hk_hap_pair_storage_put function of the HomeKit implementation, which listens on TCP port 8080 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-28469.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-3560
-
cpe:2.3:h:philips:hue_bridge_v2:-
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01028090
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01029624
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01030262
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01031131
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01032318
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01033370
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01033989
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01035934
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01036562
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01036659
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01038390
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:01039019
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1705121051
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1707040932
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1709131301
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1711151408
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1801260942
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1802201122
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1804201116
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1806051111
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1808300701
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1809121051
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1811120916
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1901181309
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1931069120
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1931140050
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1932073040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1932126170
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1933087030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1933144020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1934058060
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1934129020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1935074050
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1935144020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1935144040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:19370450000
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1937113020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1938052050
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1938052051
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1938052060
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1938052061
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1938052070
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1938052071
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1938112040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1939070020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1940042020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1940094000
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1941056000
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1941132070
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1942135050
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1943082030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1943185030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1944102110
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1944193080
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1945091050
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1945163030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1946080020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1946157000
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1947054040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1947054060
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1947108030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1948086000
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1949107040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1949203030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1950111030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1950207110
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1951086030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1951146040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1952043030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1952086010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1952086020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1952154030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1953090030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1953188020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1955082050
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1956046040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1957113050
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1957200040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1958077010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1959097030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1959194030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1960062030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1960149090
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1961076030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1961135030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1962097030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1962154010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1963089030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1963171020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1964061010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1964117020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1965017030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1965053020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1965053040
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1965111030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:196606010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1966117030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1967054010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1967054020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1968096020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1969060020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1969152010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1970084010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1970188010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1971060010
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1972004020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1972076030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1973038060
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1973146020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1974063020
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1974142030
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1975104000
-
cpe:2.3:o:philips:hue_bridge_v2_firmware:1975134020