CVE-2023-5878

Severity CVSS v4.0:
CRITICAL
Type:
CWE-77 Command Injection
Publication date:
06/02/2025
Last modified:
18/02/2025

Description

Honeywell OneWireless <br /> <br /> Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to <br /> <br /> R322.3, R330.2 or the most recent version of this product2.

References to Advisories, Solutions, and Tools