---
id: CVE-2026-5433
title: "Honeywell Control\nNetwork Module (CNM)\_contains command injection vulnerability\nin the web interface"
summary: "Honeywell Control\nNetwork Module (CNM)\_contains command injection vulnerability\nin the web interface. An attacker could exploit this vulnerability via command\ndelimiters, potentially resulting in Remote Code Execution (RCE).\_\n\n\n\nHoneywel…"
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
published: '2026-05-21'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5433'
references:
  - url: 'https://www.honeywell.com/us/en/product-security'
    label: psirt@honeywell.com
tags:
  - nvd
ingestedAt: '2026-07-27T15:20:48.217Z'
epss: 0.01551
epssPercentile: 0.73995
---

## Overview

Honeywell Control
Network Module (CNM) contains command injection vulnerability
in the web interface. An attacker could exploit this vulnerability via command
delimiters, potentially resulting in Remote Code Execution (RCE). 



Honeywell
recommends updating to the most recent version of this product, service or
offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
