CVE-2026-13248
Last modified
CVE-2026-13248 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal command interpreter. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability..
Description
An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal command interpreter. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | PD45 Industrial Printer | >= F10.19.010040, < F10.22.030745 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-13248?
How severe is CVE-2026-13248?
How do I fix CVE-2026-13248?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13242Improper Neutralization of Special Elements used in an SQL C…6.5
- CVE-2026-13243Cross-Site Request Forgery (CSRF) vulnerability in Drupal Sa…4.8
- CVE-2026-13244Improperly Controlled Modification of Dynamically-Determined…8.1
- CVE-2026-13245The MaxButtons – Create buttons plugin for WordPress is vuln…6.1
- CVE-2026-13246The GiveWP – Donation Plugin and Fundraising Platform plugin…6.4
- CVE-2026-13247The Logo Slider – Logo Carousel, Client Logo Slider & Brand …6.4
- CVE-2026-13249An unauthenticated Remote Code Execution via Arbitrary File …9.8
- CVE-2026-1325A security flaw has been discovered in Sangfor Operation and…9.8
- CVE-2026-13250The Solace Extra plugin for WordPress is vulnerable to autho…5.3
- CVE-2026-13251The Perfmatters plugin for WordPress is vulnerable to Direct…7.5
- CVE-2026-13252The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, N…6.4
- CVE-2026-13253The Ultimate Post plugin for WordPress is vulnerable to Stor…6.4
Are you affected by CVE-2026-13248?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
