OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-13248

HIGH · CVSS 8.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability in the Honeywell PD45 Industrial Printer allows authenticated users with admin or itadmin access to execute arbitrary commands through the printer's web management interface, potentially leading to remote code execution. This poses a significant risk as attackers could exploit this flaw to run malicious files on the device. Organizations using this printer model should prioritize updating to firmware version F10.22.030745 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-13248
Severity
HIGH
CVSS
8.8
EPSS
0.44%

Original NVD Description

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal command interpreter.  An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.