← Browse

CVE-2026-5433

Medium

Elevated severity or exploit probability.

CVSS base
9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.6%
74.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-77
Published 2026-05-21 · modified 2026-07-30

Description

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).  Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].

References

Official: NVD · CVE.org