CVE-2026-13249: Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication.
An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Honeywell PD45 Industrial Printerto a version that resolves this vulnerability.Fixed in F10.22.030745
Event History
Frequently Asked Questions
Which devices are exposed to this issue?
Honeywell PD45 Industrial Printers running firmware F10.19.010040 are affected through their web management interface. The issue can be exploited remotely over the network.
Does exploitation require credentials or user interaction?
No. The vulnerability is unauthenticated and requires neither privileges nor user interaction.
What can an attacker do if exploitation succeeds?
An attacker can upload attacker-controlled files through the web management interface and potentially execute malicious files and commands. This can result in remote code execution with high impact to confidentiality, integrity, and availability.
What firmware should be installed to remediate the issue?
Honeywell recommends updating to PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.