External risk intelligence

Honeywell PD45 Printer Unauthenticated Remote Code Execution via Arbitrary File Upload

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-13249

The vulnerability resides in the web management interface of an industrial printer. While these devices are ideally placed on internal networks, web management interfaces for networked appliances are commonly misconfigured or inadvertently exposed to the internet, and the requirement for no authentication makes the interface a direct, reachable target when exposed.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the web management interface of certain industrial printers, allowing unauthenticated attackers to upload and execute malicious files. This could potentially lead to unauthorized command execution on the affected devices. The primary concern is to confirm if these specific printers are exposed and accessible externally, as this type of device is typically managed internally.

  • Unauthenticated file upload allows command execution.
  • Potential for external access to printer management.
  • Confirm relevance and exposure for affected devices.

Attack Path

How an attacker could exploit the issue

An attacker could gain unauthorized access to the Honeywell PD45 Industrial Printer through its web management interface. By uploading a specially crafted file, they could execute arbitrary code on the device, potentially leading to compromised operations.

  • No authentication needed for access.
  • Upload malicious files via the web interface.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to upload and execute arbitrary files through the web management interface of the Honeywell PD45 Industrial Printer.

  • Data or system asset at risk: Printer functionality and potentially connected systems.
  • How exposure could happen: Uploading malicious files via the web interface.
  • Realistic consequence: Compromised printer operation and command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the web management interface of Honeywell PD45 Industrial Printers. Owners of these devices, likely operational technology (OT) or industrial control system (ICS) teams, should first identify all instances of this printer model and determine if their web interfaces are exposed externally or accessible to unauthenticated users. Confirming business criticality and locating the asset owner will be crucial before planning remediation.

  • OT/ICS teams own this issue.
  • Verify external or unauthenticated access.
  • Plan firmware updates during maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Honeywell PD45 Industrial Printer?

The Honeywell PD45 is an industrial label and barcode printer used in manufacturing, warehousing, and logistics environments for high-volume printing tasks. These devices include a web-based management interface that allows administrators to configure network settings, manage print jobs, and update device firmware remotely over the local network.

What does CVE-2026-13249 mean for printer security?

This vulnerability involves Unrestricted Upload of File with Dangerous Type (CWE-434) and Missing Authentication for Critical Function (CWE-306). Essentially, the printer's web interface allows anyone to upload files to the device without checking who they are. Because the device does not verify the file type or the user, an attacker can upload malicious code and trigger command execution (CWE-78) on the printer hardware.

How does an attacker trigger this printer vulnerability?

An attacker triggers this by accessing the printer's web management interface over a network connection and uploading a malicious file through the upload function. Authentication is not required, meaning the printer accepts the upload immediately. A legitimate print job sent through standard printing protocols that do not utilize the web management interface would not trigger this specific upload-based vulnerability.

Do I need to worry if my printer is not on the internet?

Halo Surface Signal indicates that while these devices are designed for internal networks, their web interfaces are often inadvertently exposed. If your printer is strictly isolated on an internal network without internet access, the likelihood of a remote, unauthenticated attacker reaching the web interface is significantly reduced. However, internal users or compromised devices on your local network could still interact with the interface.

When should I update my Honeywell PD45 firmware?

You should plan to update to firmware version F10.22.030745 as soon as your operational schedule permits. Since this is an industrial device, coordinate with your OT or ICS teams to schedule the update during a maintenance window to avoid service disruptions. As a first step, audit your network to identify all instances of this model and verify whether their management interfaces are accessible to unauthorized users.

References