CVE-2026-13248
Deferred Deferred - Pending Action

Authenticated RCE via Arbitrary File Write in Honeywell PD45 Printer

Vulnerability report for CVE-2026-13248, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Honeywell International Inc.

Description

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal command interpreter.  An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Authenticated Remote Code Execution vulnerability via Arbitrary File Write in the Intermec Fingerprint Command Interface affecting Honeywell PD45 Industrial Printers. An authenticated user with admin or itadmin access can submit commands in the Intermec Fingerprint programming language to the printer's internal command interpreter, potentially leading to malicious file and command execution.

Detection Guidance

This vulnerability can be detected by checking the firmware version of the Honeywell PD45 Industrial Printer. If the version is below F10.22.030745, it is vulnerable. Use the printer's web interface or command line to verify the firmware version.

Impact Analysis

An attacker could exploit this to execute arbitrary code on the printer, potentially gaining control over the device. This may lead to unauthorized access, data theft, or disruption of printer operations. The impact depends on the printer's role in the network and the privileges of the compromised account.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR or HIPAA. Organizations using affected printers must address this risk to maintain regulatory compliance, as unauthorized code execution could expose sensitive data.

Mitigation Strategies

Immediately update the printer's firmware to version F10.22.030745 or later, as recommended by Honeywell. Restrict access to admin and itadmin accounts to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13248. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart