Skip to content
honeywellCVE-2026-13249

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.

Critical9.8CVE-2026-13249 · Published Sep 24, 2026

Source advisory

Affected versions

PackageAffectedFixed in
PD45 Industrial Printer
Vendor
>= F10.19.010040, < F10.22.030745F10.22.030745
Details and references

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
no source yet
Weakness
CWE-78, CWE-306, CWE-434

More honeywell advisories

All
DateAdvisory
Sep 24An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer...
CVE-2026-13248High8.8fixed in PD45 Industrial Printer F10.22.030745
Jul 27Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.
CVE-2026-17612Medium6.9no fix yet
Jul 23Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows...
CVE-2026-11804Medium5.2fixed in Niagara Framework 4.14.6, Niagara Framework 4.15.5, Niagara Enterprise Security 4.14.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.