CVE-2026-13249
Deferred Deferred - Pending Action

Unauthenticated Remote Code Execution in Honeywell PD45 Industrial Printer

Vulnerability report for CVE-2026-13249, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Honeywell International Inc.

Description

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated Remote Code Execution vulnerability via Arbitrary File Upload in the web management interface of Honeywell PD45 Industrial Printer version F10.19.010040. It allows attackers to upload malicious files without authentication, which can then be executed to run arbitrary commands on the affected system.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized file uploads or suspicious activity in the Honeywell PD45 Industrial Printer web management interface. Monitor network traffic for unexpected file uploads to the printer. Check printer logs for unusual file types or uploads from unknown sources. Ensure the printer is running the latest firmware version F10.22.030745.

Impact Analysis

An attacker could exploit this to execute malicious files and commands on the printer, potentially gaining control over the device. This could lead to unauthorized access, data theft, or disruption of printer operations, impacting confidentiality, integrity, and availability of the system.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations using the affected printer may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately update the Honeywell PD45 Industrial Printer firmware to version F10.22.030745, which includes a fix for this vulnerability. Restrict access to the web management interface by implementing network-level controls or authentication. Monitor for any signs of exploitation and remove any unauthorized files uploaded to the printer.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13249. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart