PT-2026-42440 · Honeywell · Control Network Module

CVE-2026-5433

·

Published

2026-05-21

·

Updated

2026-07-28

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Honeywell Control Network Module (CNM) versions 100.1, 101.1, 110.1, and 110.2
Description The web interface contains a command injection flaw. An attacker can use command delimiters to execute arbitrary commands, which may lead to Remote Code Execution (RCE), a state where an attacker can run any command on the target machine.
Recommendations Update versions 100.1, 101.1, 110.1, and 110.2 to version 200.1.

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5433

Affected Products

Control Network Module