CVE-2023-5878
Severity CVSS v4.0:
CRITICAL
Type:
CWE-77
Command Injection
Publication date:
06/02/2025
Last modified:
18/02/2025
Description
Honeywell OneWireless <br />
<br />
Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to <br />
<br />
R322.3, R330.2 or the most recent version of this product2.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
Base Score 3.x
9.10
Severity 3.x
CRITICAL



