CVE-2026-4272
8.1Honeywell · Handheld Scanners
A missing authentication vulnerability in Honeywell Handheld Scanners allows unauthenticated remote attackers within Bluetooth range to execute system commands on the host device.
Executive summary
Honeywell Handheld Scanners are vulnerable to a high-severity authentication bypass that permits unauthorized remote command execution by attackers within Bluetooth range.
Vulnerability
The device suffers from a Missing Authentication for Critical Function (CWE-306) flaw, which enables an unauthenticated attacker located within Bluetooth range of the base station to perform unauthorized actions on the connected host.
Business impact
The ability for an unauthorized party to execute system commands on a host device poses a significant security risk, potentially leading to full system compromise, lateral movement within the network, or data exfiltration. With a CVSS score of 8.1, this vulnerability is classified as High, reflecting the potential for severe impact on organizational confidentiality and integrity despite the proximity requirement.
Remediation
Immediate Action: Upgrade the scanner base station firmware to the versions specified in the vendor advisory to resolve the authentication flaw.
Proactive Monitoring: Monitor network and system access logs for anomalous command execution patterns or unauthorized Bluetooth pairing attempts originating near critical infrastructure.
Compensating Controls: Restrict physical access to areas where scanner base stations are deployed and disable Bluetooth discovery on the host systems when not strictly required.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Given the potential for remote code execution, organizations utilizing Honeywell Handheld Scanners must prioritize the application of the provided firmware updates. Security teams should verify the specific base station model and version to ensure the correct patch is applied, thereby eliminating the risk of unauthenticated command injection.
More Honeywell CVEs
Sources
Originally found and disclosed by Kaspersky, Haidar Kabibo, per the CVE Program record.