DevSecOps Toolkit

CVE record

CVE-2026-5433

CRITICALCVSS 9.1

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).

Vulnerability metadata

Published
2026-05-21T03:46:30.270Z
Modified
2026-05-21T09:56:35.653Z
EPSS
Not available
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

References