Executive brief
Honeywell handheld barcode scanners are used in retail, logistics, and industrial environments to track inventory and process transactions. A security flaw allows an unauthorized person within Bluetooth range to bypass security checks and run commands on the computer connected to the scanner's base station. This could lead to the theft of sensitive data or the disruption of business operations.
Technical details
A Missing Authentication for Critical Function (CWE-306) vulnerability exists in several Honeywell Handheld Scanner base stations, including the C1, D1, and A1/B1 models. The flaw allows an unauthenticated attacker within Bluetooth range of the base station to abuse the communication protocol to execute arbitrary system commands on the host machine connected to the scanner. While the CVSS vector provided by the vendor indicates a network attack vector with user interaction, the description specifically highlights the proximity-based Bluetooth vector. Honeywell has released firmware updates to address this issue and recommends immediate upgrades.
Affected products
- Honeywell Handheld Scanners C1 Base (Ingenic x1000) before GK000432BAA
- Honeywell Handheld Scanners D1 Base (Ingenic x1600) before HE000085BAA
- Honeywell Handheld Scanners A1/B1 Base (IMX25) before BK000763BAA_BK000765BAA_CU000101BAA
Timeline
- 2026-04-05: disclosed
- 2026-04-05: advisory