CVE-2026-13248
8.8Honeywell · PD45 Industrial Printer
An authenticated remote code execution vulnerability in the Honeywell PD45 Industrial Printer allows command injection via the Intermec Fingerprint interface.
Executive summary
A critical vulnerability in the Honeywell PD45 Industrial Printer permits authenticated users to execute arbitrary code, posing a significant risk of unauthorized system control.
Vulnerability
This vulnerability involves improper neutralization of special elements used in OS commands and unrestricted file uploads within the web management interface. An attacker possessing valid admin or itadmin credentials can submit malicious Intermec Fingerprint language commands to the printer command interpreter, resulting in arbitrary file writes and code execution.
Business impact
Successful exploitation grants an attacker full control over the affected printing device, which can be leveraged to pivot into the internal network or disrupt critical business operations. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk that could lead to complete loss of confidentiality, integrity, and availability of the impacted hardware.
Remediation
Immediate Action: Update the firmware of all affected Honeywell PD45 Industrial Printers to version F10.22.030745 or later to resolve the underlying command injection flaw.
Proactive Monitoring: Review web management interface access logs for unauthorized attempts to access administrative functions or suspicious activity involving the Intermec Fingerprint command structure.
Compensating Controls: Restrict access to the printer web management interface to trusted administrative IP addresses via firewall rules to prevent unauthorized users from reaching the vulnerable endpoint.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Honeywell PD45 Industrial Printers must prioritize the transition to firmware version F10.22.030745. Given that this flaw allows for arbitrary file writes and command execution, leaving these devices unpatched exposes the network to potential compromise by any actor who gains access to administrative credentials.
More Honeywell CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Matheus Vianna Silveira, per the CVE Program record.