Improper sanitization
Summary
| CVE | CVE-2026-5433 |
|---|---|
| State | PUBLISHED |
| Assigner | Honeywell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-21 09:16:30 UTC |
| Updated | 2026-07-27 15:17:06 UTC |
| Description | Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE). Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2]. |
Risk And Classification
Primary CVSS: v3.1 9.1 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.003180000 probability, percentile 0.551140000 (date 2026-06-02)
Problem Types: CWE‑77 – Improper Neutralization of Special Elements
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Honeywell International Inc. | Control Network Module CNM | affected 100.1 110.2 cpe | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.honeywell.com/us/en/product-security | [email protected] | www.honeywell.com | |
| process.honeywell.com | MITRE | process.honeywell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andreas Krämer, BASF Digital Solutions GmbH (en)
CNA: Martin Floeck, BASF Digital Solutions GmbH (en)
CNA: Stefan Stahl, BASF Digital Solutions GmbH (en)
There are currently no legacy QID mappings associated with this CVE.