← All Advisories

Honeywell Control Network Module Web Interface Allows Command Delimiter Injection, Potentially Enabling Remote Code Execution via the Web Management Interface

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-5433

Key Details

CVECVE-2026-5433
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-07-30
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection'))

What to Know

Honeywell Control

Network Module (CNM) contains command injection vulnerability

in the web interface. An attacker could exploit this vulnerability via command

delimiters, potentially resulting in Remote Code Execution (RCE). 

Honeywell

recommends updating to the most recent version of this product, service or

offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2]. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-5433
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-5433