Executive brief
The Honeywell Control Network Module (CNM), which manages industrial communication networks, contains a security flaw in its web management interface. An attacker with administrative access could use this vulnerability to run unauthorized commands on the system. This could lead to a complete takeover of the module, potentially disrupting industrial operations or compromising sensitive infrastructure data.
Technical details
A command injection vulnerability exists in the web interface of the Honeywell Control Network Module (CNM). The flaw is rooted in improper sanitization of input containing command delimiters. An attacker with high privileges (PR:H) can exploit this over the network to execute arbitrary commands on the underlying operating system. Successful exploitation results in Remote Code Execution (RCE) with a scope change (S:C), indicating the potential to impact components beyond the web interface itself.
Affected products
- Honeywell Control Network Module (CNM)
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory