{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-5433", "assignerOrgId": "0dc86260-d7e3-4e81-ba06-3508e030ce8d", "state": "PUBLISHED", "assignerShortName": "Honeywell", "dateReserved": "2026-04-02T16:12:22.574Z", "datePublished": "2026-05-21T08:35:31.438Z", "dateUpdated": "2026-07-30T16:50:21.691Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "0dc86260-d7e3-4e81-ba06-3508e030ce8d", "shortName": "Honeywell", "dateUpdated": "2026-07-27T14:03:02.626Z" }, "title": "Improper sanitization", "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE‑77 – Improper Neutralization of Special Elements" } ] } ], "impacts": [ { "descriptions": [ { "lang": "en", "value": "CAPEC‑248 – Command Injection" } ] } ], "affected": [ { "vendor": "Honeywell International Inc.", "product": "Control Network Module (CNM)", "versions": [ { "status": "affected", "version": "100.1", "lessThanOrEqual": "110.2", "versionType": "cpe" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Honeywell Control\nNetwork Module (CNM) contains command injection vulnerability\nin the web interface. An attacker could exploit this vulnerability via command\ndelimiters, potentially resulting in Remote Code Execution (RCE). \n\n\n\nHoneywell\nrecommends updating to the most recent version of this product, service or\noffering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
Honeywell Control\nNetwork Module (CNM) contains command injection vulnerability\nin the web interface. An attacker could exploit this vulnerability via command\ndelimiters, potentially resulting in Remote Code Execution (RCE).
Honeywell\nrecommends updating to the most recent version of this product, service or\noffering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
" } ] } ], "references": [ { "url": "https://www.honeywell.com/us/en/product-security" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "CRITICAL", "baseScore": 9.1, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" } } ], "credits": [ { "lang": "en", "value": "Andreas Krämer, BASF Digital Solutions GmbH", "type": "finder" }, { "lang": "en", "value": "Martin Floeck, BASF Digital Solutions GmbH", "type": "finder" }, { "lang": "en", "value": "Stefan Stahl, BASF Digital Solutions GmbH", "type": "finder" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.2" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-77", "lang": "en", "description": "CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')" } ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-05-21T12:38:39.246019Z", "id": "CVE-2026-5433", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-07-30T16:50:21.691Z" } } ] } }