CVE-2026-5433
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in R...
Affects 0 products across 1 vendor.
The Honeywell Control Network Module (CNM) contains a command injection vulnerability in its web interface, which could allow an attacker to achieve Remote Code Execution (RCE). The vulnerability has a CVSS score of 9.1, indicating a high severity level. Immediate attention is required to mitigate the risk of potential exploitation.
BSID: BS-2026-GLOBAL-154097-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-5433?
What is the CVSS score for CVE-2026-5433?
Is CVE-2026-5433 actively exploited?
How do I remediate CVE-2026-5433?
What systems are affected by CVE-2026-5433?
What NERC-CIP standard applies to CVE-2026-5433?
What IEC 62443 requirement maps to CVE-2026-5433?
| CVE ID | CVE-2026-5433 |
|---|---|
| BSID | BS-2026-GLOBAL-154097-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-05-21 |
| Last Modified | 2026-07-27 |
| ICS Relevance | 55% |
| Verticals | |
| Source | NVD |
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE). Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
Source: NIST NVD / MITRE CVE Database
An attacker can exploit this vulnerability by injecting command delimiters into the web interface of the Honeywell Control Network Module (CNM). This can lead to Remote Code Execution (RCE), allowing the attacker to execute arbitrary commands on the affected system.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Honeywell | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict input validation and sanitization for all web interface inputs to prevent command injection attacks. Consider deploying a Web Application Firewall (WAF) to monitor and block suspicious traffic.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to the control network module, which could compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 because it involves a command injection vulnerability that could lead to remote code execution, compromising the integrity and availability of the control system.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 4aac03e432221e6d6b7d7ce1eec5a59506861b2c2e44cb3dcbae6703e41d828da8f6980a2edc6544431fcd163143e3c4b7f1d34cc2e070b4ad757316e908ae31 |
Critical Severity - Know Your Exposure
A CVSS 9.1 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →