CVE-2026-13249

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-306CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-26: 109-26
Referenced assets1 URL
By indicator
Full discourse1 post
  • mürrez@murrezsec

    CVE-2026-13249 — Honeywell PD45 Industrial Printer Unauth arbitrary file upload on HTTPS web admin (firmware F10.19.010040 → before F10.22.030745) → RCE. CVSS 9.8 Critical · fix: F10.22.030745 IoT/OT · Python exploit PoC → https://pocbit.org/pocs/cve-2026-13249 #CVE #IoT #OT #Honeywell

    1003090
    607 followersView on X

Explore more