CVE-2026-5433: Improper sanitization
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).
Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5433?
CVE-2026-5433 has a critical severity rating of 9.1.
What is the risk associated with CVE-2026-5433?
CVE-2026-5433 carries a risk score of 72, indicating a significant potential for exploitation.
How do I fix CVE-2026-5433?
To mitigate CVE-2026-5433, ensure that the Honeywell Control Network Module (CNM) is updated with the latest security patches from Honeywell.
What type of vulnerability is CVE-2026-5433?
CVE-2026-5433 is categorized as a command injection vulnerability.
What potential impact does CVE-2026-5433 have if exploited?
Exploitation of CVE-2026-5433 could allow an attacker to achieve remote code execution (RCE) on the affected system.