CVE-2026-13249

9.8

Honeywell · PD45 Industrial Printer

Honeywell PD45 industrial printers are vulnerable to unauthenticated remote code execution due to improper file upload validation in the web management interface.

Executive summary

An unauthenticated remote code execution vulnerability in the Honeywell PD45 Industrial Printer web interface poses a critical risk of full system compromise.

Vulnerability

This flaw involves an unrestricted arbitrary file upload vulnerability within the web management interface that lacks necessary authentication checks, allowing unauthenticated attackers to execute arbitrary system commands.

Business impact

The criticality of this vulnerability is underscored by its CVSS score of 9.8, reflecting the ability for an attacker to gain complete control over the affected hardware without requiring credentials. Successful exploitation could lead to total loss of confidentiality, integrity, and availability of the printer, potentially allowing lateral movement into the wider internal network.

Remediation

Immediate Action: Update the firmware of all affected Honeywell PD45 Industrial Printers to version F10.22.030745 or later immediately.

Proactive Monitoring: Review web server access logs for unusual POST requests or file upload attempts targeting the management interface, particularly those originating from unauthorized IP addresses.

Compensating Controls: Restrict access to the printer web management interface to trusted administrative subnets only via network access control lists or firewall rules to prevent external exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity and the ease of exploitation over the network, this vulnerability requires immediate attention. Security teams must prioritize firmware updates for all deployed PD45 units to the specified version or higher to eliminate the risk of remote code execution.

More Honeywell CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Matheus Vianna Silveira, per the CVE Program record.