Honeywell Control
Network Module (CNM) contains command injection vulnerability
in the web interface. An attacker could exploit this vulnerability via command
delimiters, potentially resulting in Remote Code Execution (RCE).
Honeywell
recommends updating to the most recent version of this product, service or
offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
References
| Link | Resource |
|---|---|
| https://www.honeywell.com/us/en/product-security |
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-21 09:16
Updated : 2026-07-30 19:18
NVD link : CVE-2026-5433
Mitre link : CVE-2026-5433
CVE.ORG link : CVE-2026-5433
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
