Signify · Hue Bridge Pro · CVE-2026-73669
**Name of the Vulnerable Software and Affected Versions**
Signify Philips Hue Bridge Pro versions prior to 1.77.2071318010
**Description**
The firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces with anonymous access enabled and no firewall restrictions. This allows an unauthenticated attacker with network access to the service to read device data and control connected lights.
**Recommendations**
Update to version 1.77.2071318010.