OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13249

CRITICAL · CVSS 9.8 EPSS 0.57% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability in Honeywell PD45 Industrial Printer's web management interface allows unauthenticated remote code execution through arbitrary file uploads, enabling attackers to execute malicious files and commands. Organizations using this printer model should prioritize immediate updates to firmware version F10.22.030745 to mitigate the risk of exploitation. Given the critical severity rating, all users of the affected product are strongly advised to address this issue without delay.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-13249
Severity
CRITICAL
CVSS
9.8
EPSS
0.57%

Original NVD Description

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.