CVE-2026-13249
Last modified
CVE-2026-13249 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability..
Description
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | PD45 Industrial Printer | >= F10.19.010040, < F10.22.030745 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-13249?
How severe is CVE-2026-13249?
How do I fix CVE-2026-13249?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13243Cross-Site Request Forgery (CSRF) vulnerability in Drupal Sa…4.8
- CVE-2026-13244Improperly Controlled Modification of Dynamically-Determined…8.1
- CVE-2026-13245The MaxButtons – Create buttons plugin for WordPress is vuln…6.1
- CVE-2026-13246The GiveWP – Donation Plugin and Fundraising Platform plugin…6.4
- CVE-2026-13247The Logo Slider – Logo Carousel, Client Logo Slider & Brand …6.4
- CVE-2026-13248An Authenticated Remote Code Execution via Arbitrary File Wr…8.8
- CVE-2026-1325A security flaw has been discovered in Sangfor Operation and…9.8
- CVE-2026-13250The Solace Extra plugin for WordPress is vulnerable to autho…5.3
- CVE-2026-13251The Perfmatters plugin for WordPress is vulnerable to Direct…7.5
- CVE-2026-13252The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, N…6.4
- CVE-2026-13253The Ultimate Post plugin for WordPress is vulnerable to Stor…6.4
- CVE-2026-1326A weakness has been identified in Totolink NR1800X 9.1.0u.62…8.8
Are you affected by CVE-2026-13249?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
